HackingCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumContained
Durvet
bd_6f70144973a84200 · schema v1 · pii pii-v1
Full breach record for Durvet →On October 17–18, 2025, Durvet, Inc. experienced unauthorized access to its IT environment, during which certain data was copied and taken. The breach was discovered on February 18, 2026, following a comprehensive forensic review. Information affected included names and Social Security numbers. One Maine resident was affected out of 148 total. Written notification was sent March 17, 2026. Durvet offered 24 months of credit monitoring through Epiq.
Leak gap clock⏱ Leak >90d27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by qilin about this victim predates this filing by 151 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_40bb3317d36bd649Leak Siteqilinfiled 2025-11-05(132d gap)Candidate
- bd_6f2ca69d7fee4e8aLeak Siteqilinfiled 2025-10-17(151d gap)Verified by operator
Regulatory filings (1) · sorted by filing gap
- bd_acb081d981062056Indiana State AGfiled 2026-03-17Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1e729fe1-f7ae-4383-adaf-227eb91bd5b8.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2026
- Raw hash
- 9cae4a084d9fa880a2cce2375540e843cc6f03e7d6e4bbbed2f23f5984bc679d
Reporting entity
- Name
- Durvetnorm: durvet
- Domain
- durvet.com
- Industry
- Other Commercial
Victim entity
- Name
- Durvetnorm: durvet
- Domain
- durvet.com
- Industry
- Other Commercial
Incident
- Discovered
- Feb 18, 2026
- Materiality determined
- —
- Notification sent
- Mar 17, 2026
- Affected individuals
- 1
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Written notice provided to Maine Attorney GeneralNotice to three major credit reporting agencies: Equifax, Experian, TransUnion
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- Leak >90dME AG ≤30d · 27d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 18, 2026→ Filed with AG: Mar 17, 202627d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.