MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedIDENTITY_BASICLowContained
American Associated Pharmacies
bd_740593241b9440ec · schema v1 · pii pii-v1
Full breach record for American Associated Pharmacies →American Associated Pharmacies (AAP) disclosed a ransomware incident detected on October 23, 2024, with initial access occurring October 13, 2024. The attacker encrypted systems and exfiltrated data, potentially including names and addresses. AAP proactively shut down systems, reset passwords, engaged forensic experts, and notified law enforcement. AAP is offering credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday13 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
A leak claim by embargo about this victim predates this filing by 364 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_026dc026d7edd520Leak Siteembargofiled 2024-11-12(364d gap)Verified
Regulatory filings (4) · sorted by filing gap
- bd_5752d2fa56e1021fCalifornia State AGfiled 2025-11-12Verified
- bd_6f03581859047e74Maine State AGfiled 2025-11-12Candidate
- bd_a055985a15fb12b5Montana State AGfiled 2025-11-12Verified
- bd_fe8758ed5a20a130Washington State AGfiled 2025-11-12Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-12-american-associated-pharmacies-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 12, 2025
- Raw hash
- 4f651e54f0e48d534e9035b619156344ac15fc8237954c5742c688693eefd717
Reporting entity
- Name
- American Associated Pharmaciesnorm: american associated pharmacies
Victim entity
- Name
- American Associated Pharmaciesnorm: american associated pharmacies
Incident
- Discovered
- Oct 23, 2024
- Materiality determined
- Nov 12, 2025
- Notification sent
- Nov 11, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reporting this Incident to relevant government agencies
Compliance
- Time to disclose
- 13 months(385 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.