HackingVulnerability ExploitStolen CredentialsData ExfiltratedTargetedPIIIDENTITY_BASICLowContained
Jeff Anderson & Associates PA
bd_685ea336212807ca · schema v1 · pii pii-v1
Full breach record for Jeff Anderson & Associates PA →Jeff Anderson & Associates PA notified consumers of a data breach discovered in September 2025. An unauthorized party accessed systems via a vulnerability in firewall protection technology used by multiple organizations. The firm engaged cybersecurity specialists, notified law enforcement, and is offering 24 months of credit monitoring. The specific data types affected were redacted in the sample notice provided.
Vermont clock✗ VT AG >45 bday23 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_116d30fdd32f2efdCalifornia State AGfiled 2026-02-26Verified
- bd_4d61d64c2f99c415California State AGfiled 2026-02-10(16d gap)Verified
- bd_17b24dde1fc4edb5Indiana State AGfiled 2025-12-19(69d gap)Candidate
- bd_91b364a07fe72e9cNew Hampshire State AGfiled 2025-12-19(69d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-26-jeff-anderson-associates-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 26, 2026
- Raw hash
- 2db88e1f20df434e185460dbfc20a98aeb50eff5151699eb557a3e5040353abe
Reporting entity
- Name
- Jeff Anderson & Associates PAnorm: jeff anderson associates
- Domain
- andersonsadvocates.com
Victim entity
- Name
- Jeff Anderson & Associates PAnorm: jeff anderson associates
- Domain
- andersonsadvocates.com
Incident
- Discovered
- Sep 18, 2025
- Materiality determined
- Feb 26, 2026
- Notification sent
- Feb 26, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 weeks(161 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.