HackingStolen CredentialsCapture Stored DataData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPIIMediumContained
Fundamental Administrative Services, LLC
bd_77eb9da16590123a · schema v1 · pii pii-v1
Full breach record for Fundamental Administrative Services, LLC →Fundamental Administrative Services LLC notified consumers of a security incident where an unauthorized actor copied files from its network between October 27, 2024, and January 13, 2025. Affected data includes names, SSNs, driver's licenses, financial account info, and medical/insurance details. Fundamental offered credit monitoring and enhanced security measures.
Vermont clock✗ VT AG >45 bday30 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_445273654278dca0Indiana State AGfiled 2025-08-15Verified
- bd_2f89919848471f4fTexas State AGfiled 2025-08-19(4d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-08-15-fundamental-administrative-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 15, 2025
- Raw hash
- c63039bd924b5f6fe49786b63d6c7d55398e4089c07f6742eab0998f9244858e
Reporting entity
- Name
- Fundamental Administrative Services, LLCnorm: fundamental administrative
Victim entity
- Name
- Fundamental Administrative Services, LLCnorm: fundamental administrative
Incident
- Discovered
- Jan 20, 2025
- Materiality determined
- —
- Notification sent
- Aug 15, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 30 weeks(207 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.