HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
BHI Energy I Specialty Services LLC
bd_6b70bd566e3b8be6 · schema v1 · pii pii-v1
Full breach record for BHI Energy I Specialty Services LLC →BHI Energy Specialty Services notified consumers of a data security incident discovered on June 29, 2023, involving unauthorized access to its network. The incident exposed PII including names, addresses, dates of birth, SSNs, and potentially health information. BHI engaged forensic investigators, secured systems, and offered 24 months of Experian IdentityWorks monitoring.
Vermont clock✗ VT AG >45 bday16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0058c059945a2749New Hampshire State AGfiled 2023-10-18Verified
- bd_06d2a8db0a5a2a79Washington State AGfiled 2023-10-18Candidate
- bd_36f52a39ba8b286dCalifornia State AGfiled 2023-10-18Verified
- bd_46cdc3e8aa9e883dMontana State AGfiled 2023-10-18Verified
Show 2 more filings ↓Show fewer ↑
- bd_56c902fa1f6b5407Oregon State AGfiled 2023-10-18Verified
- bd_8fa2440398ccf349Maine State AGfiled 2023-10-18Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-18-bhi-energy-specialty-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 18, 2023
- Raw hash
- 5d261965e709127479733258c3556b5f910d5806683afd4dfc29eaa32596c034
Reporting entity
- Name
- BHI Energy I Specialty Services LLCnorm: bhi energy i specialty
Victim entity
- Name
- BHI Energy I Specialty Services LLCnorm: bhi energy i specialty
Incident
- Discovered
- Jun 29, 2023
- Materiality determined
- —
- Notification sent
- Oct 18, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified state and federal agencies, as required by state privacy laws
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.