Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Cumberland Advisors, LLC
bd_70f1d52df37b37f8 · schema v1 · pii pii-v1
Full breach record for Cumberland Advisors, LLC →Cumberland Advisors, Inc. notified consumers on December 20, 2023, of unauthorized access to two employee email accounts between August 31 and September 5, 2023. The breach resulted from suspicious activity likely involving phishing, leading to credential compromise. Customer PII, including government IDs, was accessed. No misuse has been confirmed. Remediation included forensic investigation, security protocol enhancements, and complimentary credit monitoring.
Vermont clock✗ VT AG >45 bday15 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_27f60e7defb708fcMontana State AGfiled 2023-12-20Candidate
- bd_59e92d07c3db90cfMaine State AGfiled 2023-12-20Verified
- bd_6ab5b3b9d1b51cd8New Hampshire State AGfiled 2024-02-14(56d gap)Verified
- bd_e75969bf74119acfMaine State AGfiled 2024-02-14(56d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-20-cumberland-advisors-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 20, 2023
- Raw hash
- d99b8e2a5184def99d0a704b450fd1cfe10d9c2a9ccdc6889c17ad43426e2aba
Reporting entity
- Name
- Cumberland Advisors, LLCnorm: cumberland advisors
Victim entity
- Name
- Cumberland Advisors, LLCnorm: cumberland advisors
Incident
- Discovered
- Sep 5, 2023
- Materiality determined
- Dec 20, 2023
- Notification sent
- Dec 20, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.