DisclosureLens
Social EngineeringTechnologyInformationPhishingCustomer Data InvolvedIdentity (basic)Financial accountLowContained

COVETRUS, INC.

bd_69e0a341a0dd565a · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 21, 2023

Filed

May 8, 2023

To disclose

7 weeks

Affected · nationwide

1204 in this filing

Linked

3 filings

Confidence

66%
Full breach record for COVETRUS, INC.

Covetrus, Inc. reported a phishing incident occurring between November 11 and 28, 2022, discovered on March 21, 2023. The breach affected 120 individuals, including 4 Maine residents. Compromised data included names and financial account or credit/debit card numbers. Covetrus provided written notification on May 8, 2023, and offered 24 months of identity theft protection services via Kroll, LLC.

Maine clockDiscovered Mar 21, 2023Filed with AG May 8, 202348d ME AG >30d7 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 130 days
discovery → filing · 7 weeks / 48 days

Nov 11, 2022

Begins

Mar 21, 2023

Discovered

May 8, 2023

Filed

vs. sector median

12 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Montana State AGMay 8 · first
Maine State AGMay 8 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.