HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CNHI, LLC
bd_636302d394e1cd30 · schema v1 · pii pii-v1
Full breach record for CNHI, LLC →CNHI, LLC notified consumers of a data breach where an unauthorized actor accessed the network between April 27 and May 17, 2025. The incident compromised names and Social Security numbers. CNHI engaged forensic investigators, secured the network, and offered one year of Experian IdentityWorks credit monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday32 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_51267646cce26e95Indiana State AGfiled 2025-12-08Verified
- bd_5c40821d85f38cedNew Hampshire State AGfiled 2025-12-08Verified
- bd_bad5e82d02c73257South Carolina State AGfiled 2025-12-08Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-08-cnhi-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2025
- Raw hash
- b822da66906e8636b0c8dd75d5a6d310893298fb7d8c0c053fbded974641b3ec
Reporting entity
- Name
- CNHI, LLCnorm: cnhi
Victim entity
- Name
- CNHI, LLCnorm: cnhi
Incident
- Discovered
- Apr 27, 2025
- Materiality determined
- Dec 8, 2025
- Notification sent
- Dec 8, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 32 weeks(225 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.