HackingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CIBT HOLDINGS, INC.
bd_5500dde764428ef0 · schema v1 · pii pii-v1
Full breach record for CIBT HOLDINGS, INC. →CIBT, Inc., a travel visa services provider, notified consumers of a data security incident discovered on November 19, 2022. Unauthorized access to personal information, including names and government IDs, occurred. CIBT engaged cybersecurity firms for investigation, notified law enforcement, and provided 12 months of complimentary identity monitoring via Kroll to affected individuals.
Vermont clock✗ VT AG >45 bday28 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1f698b30bf706fc8California State AGfiled 2023-06-08(2d gap)Candidate
- bd_bfd10fa0735500edNew Hampshire State AGfiled 2023-06-08(2d gap)Verified
- bd_ed26c0caeec7b403Maine State AGfiled 2023-06-08(2d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-06-06-cibt-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 6, 2023
- Raw hash
- cfe4b8f8741b78287c2b3a8fea782ec4ad02f004931f80a978d0ed8840990cbb
Reporting entity
- Name
- CIBT HOLDINGS, INC.norm: cibt holdings
Victim entity
- Name
- CIBT HOLDINGS, INC.norm: cibt holdings
Incident
- Discovered
- Nov 19, 2022
- Materiality determined
- —
- Notification sent
- May 23, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 weeks(199 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.