MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICPHIMediumContained
The Hiller Companies LLC
bd_6f11cc5801ccd1dc · schema v1 · pii pii-v1
Full breach record for The Hiller Companies LLC →The Hiller Companies LLC notified consumers of a data security incident discovered on June 13, 2025. Malicious actors encrypted files and copied data from the network on or about December 18, 2024. Potentially exposed data includes names, SSNs, driver's license numbers, financial account info, payment card numbers, and medical/health insurance information. The company engaged cybersecurity experts, enhanced security measures, and offered 12 months of credit monitoring and fraud assistance via Cyberscout.
Vermont clock✗ VT AG >45 bday10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3cb094e2e1459a38Montana State AGfiled 2025-08-25Candidate
- bd_bdba02a450a666e3New Hampshire State AGfiled 2025-08-25Verified
- bd_f0fe773a8636f9b3California State AGfiled 2025-08-25Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-08-25-lp-falcon-holdings-inc-hiller-companies-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2025
- Raw hash
- 8db107499cd1e40162f528d133be751c0d3060199f03b5951d52a85ceefcefb9
Reporting entity
- Name
- The Hiller Companies LLCnorm: the hiller companies
Victim entity
- Name
- The Hiller Companies LLCnorm: the hiller companies
Incident
- Discovered
- Jun 13, 2025
- Materiality determined
- Aug 25, 2025
- Notification sent
- Aug 25, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICPHI
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 10 weeks(73 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.