Social EngineeringPhishingStolen CredentialsBECMulti-Stage ChainWire FraudCustomer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
COVETRUS, INC.
bd_7931d93d4568f830 · schema v1 · pii pii-v1
Full breach record for COVETRUS, INC. →Covetrus, Inc. reported a security event where two employee email accounts were accessed by an unauthorized actor between November 11 and November 28, 2022. The actor likely used phishing to obtain credentials and redirected payments. Personal and financial information from the affected accounts was potentially downloaded. Covetrus engaged forensic experts, notified law enforcement, and is offering two years of complimentary identity monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_69e0a341a0dd565aMaine State AGfiled 2023-05-08Candidate
- bd_f19b90c355368880Montana State AGfiled 2023-05-08Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/covetrus-20230508.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 8, 2023
- Raw hash
- e16547983c99b3e1fc0197d06bfe9f05d4f53a48125b0ba0620438f1905e8f1d
Reporting entity
- Name
- COVETRUS, INC.norm: covetrus
Victim entity
- Name
- COVETRUS, INC.norm: covetrus
Incident
- Discovered
- Nov 28, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 23 weeks(161 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.