DisclosureLens
Social EngineeringRetail & ConsumerRetailPhishingStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDFinancial accountMediumContained

Copeland Chevrolet

bd_616959e0356f4e04 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 4, 2025

Filed

Oct 22, 2025

To disclose

11 weeks

Affected

4state residents only

Linked

3 filings

Confidence

67%
Full breach record for Copeland Chevrolet

Copeland Chevrolet notified the NH AG that on August 4, 2025, suspicious activity was identified in an employee email account. The account was compromised, exposing customer names, SSNs, driver's license numbers, state IDs, and financial account information. Four NH residents were affected. Copeland secured the account, engaged forensic experts, implemented MFA, and offered 12 months of credit monitoring via Kroll.

Incident timeline

discovery → filing · 11 weeks / 79 days

Aug 4, 2025

Discovered

Oct 22, 2025

Filed

vs. sector median

+4 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Maine State AGOct 16 · first
New Hampshire State AG+6d · this page

Pattern: first filing Oct 16 (ME), last Oct 22 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.