HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Davidoff Hutcher & Citron LLP
bd_71369198ffef49ce · schema v1 · pii pii-v1
Full breach record for Davidoff Hutcher & Citron LLP →Davidoff Hutcher & Citron LLP notified consumers of a data security incident where an unauthorized party accessed its network between Jan 12 and Aug 18, 2023. The attacker may have removed files containing names and other personal info. DHC contained the threat, engaged external cybersecurity professionals, and is offering 12 months of credit monitoring. No evidence of misuse was found. The notice was filed with the Vermont AG on Aug 21, 2024.
Vermont clock✗ VT AG >45 bday12 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by alphv about this victim predates this filing by 366 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_4d665d6a92b5ce58Leak Sitealphvfiled 2023-08-21(366d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_56edfa3d945c42d0Montana State AGfiled 2024-08-20(1d gap)Verified by operator
- bd_f03d3a1a868c4286California State AGfiled 2024-08-20(1d gap)Verified by operator
- bd_3b37ea23e9b37e6bMaine State AGfiled 2024-08-09(12d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-08-21-davidoff-hutcher-citron-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 21, 2024
- Raw hash
- 9abf650c251897d733223cc84b3a70fd42a647843366efa84f2e851544af7d2e
Reporting entity
- Name
- Davidoff Hutcher & Citron LLPnorm: davidoff hutcher citron
Victim entity
- Name
- Davidoff Hutcher & Citron LLPnorm: davidoff hutcher citron
Incident
- Discovered
- Aug 18, 2023
- Materiality determined
- —
- Notification sent
- Aug 21, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 months(369 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.