HackingData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumContained
Mercer Advisors Inc.
bd_7a9028119074fbf3 · schema v1 · pii pii-v1
Full breach record for Mercer Advisors Inc. →Mercer Advisors Inc. disclosed a cybersecurity incident occurring around January 22, 2026, involving unauthorized access to systems storing client data. The breach exposed personal information including names, contact details, government IDs, dates of birth, account numbers, and in some cases SSNs and credentials. The incident was contained, and the company engaged external experts and notified law enforcement. No specific affected individual count was provided in the filing.
Vermont clock✗ VT AG >45 bday10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
A leak claim by shinyhunters about this victim predates this filing by 37 days.View originating leak claim
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-31-mercer-advisors-inc-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 31, 2026
- Raw hash
- 8dbb11cdcde2ea1f305f9501e34b073962f7df98ad029a4efe90f07c492ca2bb
Reporting entity
- Name
- Mercer Advisors Inc.norm: mercer advisors
- Domain
- merceradvisors.com
Victim entity
- Name
- Mercer Advisors Inc.norm: mercer advisors
- Domain
- merceradvisors.com
Incident
- Discovered
- Jan 22, 2026
- Materiality determined
- Mar 31, 2026
- Notification sent
- Mar 31, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the issue to law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.