HackingSupply Chain (3P Vendor)IDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Total Wireless
bd_60a42f6940cf473e · schema v1 · pii pii-v1
Full breach record for Total Wireless →Total Wireless notified Vermont AG that its third-party identity verification provider, Veriff, experienced a data breach. Unauthorized access to Veriff's systems exposed government-issued ID images, and potentially postal addresses and dates of birth, for some Total Wireless customers. Total Wireless notified law enforcement and is offering one year of free credit monitoring.
Vermont clock⏱ VT AG >14 bday4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_13f02acc3eea5958California State AGfiled 2026-01-09Candidate
- bd_421e484843bb5683Indiana State AGfiled 2026-01-09Verified
- bd_522330d0bde81a55Indiana State AGfiled 2026-01-09Verified
- bd_c7d46e788ff0b564Montana State AGfiled 2026-01-09Verified
Show 2 more filings ↓Show fewer ↑up to 4d gap
- bd_f73dbc978139c036Maine State AGfiled 2026-01-09Verified
- bd_35f9dbfd39d47241Texas State AGfiled 2026-01-13(4d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-01-09-total-wireless-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 9, 2026
- Raw hash
- 75460a345fc69efccc5b6d4cd5cc9af0544a83b75d0b21d079c7cc63f08b63d8
Reporting entity
- Name
- Total Wirelessnorm: total wireless
Victim entity
- Name
- Total Wirelessnorm: total wireless
Incident
- Discovered
- Dec 10, 2025
- Materiality determined
- —
- Notification sent
- Jan 9, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Veriff
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.