Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
Rkl LLP
bd_769fc45b4b1cd7b2 · schema v1 · pii pii-v1
Full breach record for Rkl LLP →RKL, LLP notified consumers of unauthorized access to an employee's email account between May 11 and June 19, 2023, following a spoofed email alert. The incident involved access to names and email addresses. RKL secured the account, offered credit monitoring via Identity Force, and enhanced security policies and training.
Vermont clock✗ VT AG >45 bday27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-28-rkl-data-breach-notice-consumers-0
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 28, 2023
- Raw hash
- ac191314ac00054d9314339b39e4e6e90e4d9c05088bc470133343ec2b90eb0b
Reporting entity
- Name
- Rkl LLPnorm: rkl
Victim entity
- Name
- Rkl LLPnorm: rkl
Incident
- Discovered
- Jun 19, 2023
- Materiality determined
- —
- Notification sent
- Dec 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notifying relevant regulatory authorities
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 weeks(192 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.