HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Sirius Federal
bd_579778adb1846cb6 · schema v1 · pii pii-v1
Full breach record for Sirius Federal →Sirius Federal, a subsidiary of CDW-G, notified consumers of a data breach occurring between July 31 and August 2, 2023. Unauthorized actors accessed internal servers containing names, SSNs, DOBs, health insurance info, and for a subset, financial account data. Sirius Federal engaged third-party cybersecurity experts, secured systems, enhanced security monitoring and authentication, and offered two years of credit monitoring via Experian.
Vermont clock✗ VT AG >45 bday24 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_62d7ca0f719fa8a7Montana State AGfiled 2024-01-19Candidate
- bd_780c87eef2158753Indiana State AGfiled 2024-01-19Verified
- bd_7875f0a074bf5b6eMaine State AGfiled 2024-01-31(12d gap)Verified by operator
- bd_a641d8dc75eb6cc6New Hampshire State AGfiled 2024-01-31(12d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-01-19-sirius-federal-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 19, 2024
- Raw hash
- 56f41cd236cde02878d7dfcaea8cc6724a89dd0b6f0cde475918c0dfaa6f7e75
Reporting entity
- Name
- Sirius Federalnorm: sirius federal
Victim entity
- Name
- Sirius Federalnorm: sirius federal
Incident
- Discovered
- Aug 2, 2023
- Materiality determined
- Jan 19, 2024
- Notification sent
- Jan 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 weeks(170 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.