DisclosureLens
Social EngineeringTechnologyRetail & ConsumerInformationPhishingStolen CredentialsBECMulti-Stage ChainWire FraudCustomer Data InvolvedPIIFinancial accountLowContained

COVETRUS, INC.

bd_7931d93d4568f830 · schema v1 · pii pii-v1

Severity

Low

Discovered

Nov 28, 2022

Filed

May 8, 2023

To disclose

23 weeks

Affected

Not disclosed

Linked

3 filings

Confidence

64%
Full breach record for COVETRUS, INC.

Covetrus, Inc. reported a security event where two employee email accounts were accessed by an unauthorized actor between November 11 and November 28, 2022. The actor likely used phishing to obtain credentials and redirected payments. Personal and financial information from the affected accounts was potentially downloaded. Covetrus engaged forensic experts, notified law enforcement, and is offering two years of complimentary identity monitoring.

Incident timeline

undetected · 17 days
discovery → filing · 23 weeks / 161 days

Nov 11, 2022

Begins

Nov 28, 2022

Discovered

May 8, 2023

Filed

vs. sector median

+4 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Maine State AGMay 8 · first
Montana State AGMay 8 · first
New Hampshire State AGMay 8 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.