HackingData ExfiltratedIDENTITY_BASICHEALTH_BASICPHILowContained
Arbor
bd_5c23d20e0ad3430d · schema v1 · pii pii-v1
Full breach record for Arbor →Arbor Associates, Inc. notified consumers of a data security incident where files were acquired without authorization between April 15-17, 2025. The breach potentially exposed patient survey data including names, dates of birth, medical record numbers, and diagnosis codes. Arbor engaged cybersecurity experts and enhanced security measures.
Vermont clock✗ VT AG >45 bday13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_7e87e5d560735befOregon State AGfiled 2025-07-17Verified
- bd_4477dbc38992c443Washington State AGfiled 2025-07-03(14d gap)Candidate
- bd_a984f051dd655e2fMontana State AGfiled 2025-07-03(14d gap)Verified
- bd_d13f3fd45725847aCalifornia State AGfiled 2025-07-03(14d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 26d gap
- bd_90472ab9e6074d4aMontana State AGfiled 2025-08-08(22d gap)Verified
- bd_b50fb3d4dec6d3c4California State AGfiled 2025-08-08(22d gap)Verified
- bd_a75ba824f7da509aTexas State AGfiled 2025-08-12(26d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-17-arbor-associates-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2025
- Raw hash
- e35b87b1c5f432df49d5af957f825a651e05c3bbdd3e739fe70511d5ffd1312b
Reporting entity
- Name
- Arbornorm: arbor
- Domain
- arbor-education.com
Victim entity
- Name
- Arbornorm: arbor
- Domain
- arbor-education.com
Incident
- Discovered
- Apr 17, 2025
- Materiality determined
- —
- Notification sent
- Jul 17, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.