HackingStolen CredentialsDelayed DiscoveryIDENTITY_BASICCREDENTIALSLowActive
One Point HR Solutions, Inc.
bd_546c83680572c529 · schema v1 · pii pii-v1
Full breach record for One Point HR Solutions, Inc. →One Point HR Solutions, Inc. notified consumers of a data breach involving unauthorized access to email accounts between July 2023 and February 2024. The incident involved credential compromise and email collection. The company engaged forensic specialists, notified law enforcement, and offered credit monitoring services. The investigation was ongoing at the time of notification.
Vermont clock✗ VT AG >45 bday14 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0f6b372b3dd4d5fbMaine State AGfiled 2024-09-06(1d gap)Verified
- bd_20065c46365befffNew Hampshire State AGfiled 2024-09-06(1d gap)Verified
- bd_668b3a3ee358d439Montana State AGfiled 2024-09-06(1d gap)Candidate
- bd_9c03bb465078bfc4Indiana State AGfiled 2024-09-06(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 36d gap
- bd_0086cc962bc729a6New Hampshire State AGfiled 2024-10-11(36d gap)Verified
- bd_c44fb15ebe89684aMaine State AGfiled 2024-10-11(36d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-09-05-one-point-hr-solutions-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2024
- Raw hash
- 6f4e88f1f156a182aa386892b3da65010f241c031a36566a0818eb3be3c31136
Reporting entity
- Name
- One Point HR Solutions, Inc.norm: one point hr
- Domain
- onepointhrs.com
Victim entity
- Name
- One Point HR Solutions, Inc.norm: one point hr
- Domain
- onepointhrs.com
Incident
- Discovered
- Jul 3, 2023
- Materiality determined
- Sep 5, 2024
- Notification sent
- Sep 6, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- reported the event to federal and local law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(430 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.