HackingStolen CredentialsCapture Stored DataCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Endue Software
bd_5bc86c50c5edfc76 · schema v1 · pii pii-v1
Full breach record for Endue Software →Endue Software, a healthcare software provider, notified consumers of a cybersecurity incident on Feb 16, 2025, where an unauthorized actor accessed systems and copied files. Affected data included names, DOBs, SSNs, and medical record numbers. Endue engaged law enforcement, enhanced security, and offered credit monitoring. No specific count was provided, though ~32 Rhode Island residents were noted.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_08920fbd0889d482Indiana State AGfiled 2025-04-11Verified
- bd_15dd0c0c8fb43bf4HHS OCRfiled 2025-04-11Verified
- bd_1ff35c438b26be88New Hampshire State AGfiled 2025-04-11Verified
- bd_2ba6e7caea77b873Vermont State AGfiled 2025-04-11Verified
Show 3 more filings ↓Show fewer ↑
- bd_3f9524f86d2e0052Maine State AGfiled 2025-04-11Verified
- bd_7345eadbe357342dCalifornia State AGfiled 2025-04-11Verified
- bd_96d712f75f14a6b9Montana State AGfiled 2025-04-11Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-11-endue-software-data-breach-notice-consumers-0
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2025
- Raw hash
- 13b3921a8d7b7a6ca4715d09fcb20326f50b62d551b4c221c1c7099f8c6996d9
Reporting entity
- Name
- Endue Softwarenorm: endue software
Victim entity
- Name
- Endue Softwarenorm: endue software
Incident
- Discovered
- Feb 17, 2025
- Materiality determined
- —
- Notification sent
- Apr 11, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- notified law enforcementproviding notice of this incident to relevant regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.