Social EngineeringPhishingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
The Hilb Group Operating Company, LLC
bd_5a9f4d90a4333861 · schema v1 · pii pii-v1
Full breach record for The Hilb Group Operating Company, LLC →The Hilb Group Operating Company, LLC experienced a data breach due to a phishing incident that occurred between December 1, 2022, and January 12, 2023. The breach, discovered on October 9, 2023, affected 81,539 individuals. Compromised data includes names and financial account or credit/debit card numbers along with access codes or PINs. Affected individuals were notified starting November 2, 2023, and offered 12 months of credit monitoring services through TransUnion.
Maine clockDiscovered Oct 9, 2023 → Filed with AG Nov 2, 202324d ✓ ME AG ≤30d24 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_67eab2b36e096a14Vermont State AGfiled 2023-11-02Verified
- bd_a48bfe51bd1a9f3fMontana State AGfiled 2023-11-02Verified by operator
- bd_eb73cca33de90388California State AGfiled 2023-11-02Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/efcbb550-4093-4bdf-95a0-ecd868472099.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 2, 2023
- Raw hash
- e288795b29a50feea112886e34a0b98bd75b3a26b69c0e361ddd52ee806f562c
Reporting entity
- Name
- The Hilb Group Operating Company, LLCnorm: the hilb group operating
Victim entity
- Name
- The Hilb Group Operating Company, LLCnorm: the hilb group operating
Incident
- Discovered
- Oct 9, 2023
- Materiality determined
- —
- Notification sent
- Nov 2, 2023
- Affected individuals
- 81,539
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 Phishing
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 24d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Oct 9, 2023→ Filed with AG: Nov 2, 202324d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.