HackingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
VARSITY BRANDS, INC.
bd_798edfde7bf49675 · schema v1 · pii pii-v1
Full breach record for VARSITY BRANDS, INC. →On May 24, 2024, Varsity Brands, LLC identified unusual activity on its systems and determined an unauthorized third party obtained a small subset of company files containing personal information. Varsity Brands took systems offline, engaged external cybersecurity experts, notified law enforcement, rotated credentials, and implemented additional safeguards. The company is offering 24 months of complimentary credit monitoring and identity theft protection through TransUnion to affected individuals.
Vermont clock✗ VT AG >45 bday20 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1676b54b0c515384New Hampshire State AGfiled 2024-10-14Verified
- bd_3601cb56d70fe719Washington State AGfiled 2024-10-14Candidate
- bd_5ed805070d8eaed7Maine State AGfiled 2024-10-14Verified
- bd_97714593a5bb482fIndiana State AGfiled 2024-10-14Verified
Show 2 more filings ↓Show fewer ↑
- bd_bca70a851713f822Montana State AGfiled 2024-10-14Verified
- bd_cd6bb99fcd32408aCalifornia State AGfiled 2024-10-14Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-10-14-varsity-brands-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 14, 2024
- Raw hash
- 7c0f3233f6bb9bd3db58374f27214898e8961053f48a8a1f52e526215ae94452
Reporting entity
- Name
- VARSITY BRANDS, INC.norm: varsity brands
Victim entity
- Name
- VARSITY BRANDS, INC.norm: varsity brands
Incident
- Discovered
- May 24, 2024
- Materiality determined
- —
- Notification sent
- Oct 14, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(143 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.