MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedPIIIDENTITY_BASICLowContained
New River Electrical Corp.
bd_7b611efde49729d9 · schema v1 · pii pii-v1
Full breach record for New River Electrical Corp. →New River Electrical Corp. notified consumers of a cyber-attack identified on May 6, 2024, involving system encryption and unauthorized access between April 30 and May 6, 2024. The incident resulted in the potential viewing and downloading of customer names and other data elements. New River secured systems, reported to federal law enforcement, and offered complimentary credit monitoring via Equifax.
Vermont clock✗ VT AG >45 bday30 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by eldorado about this victim predates this filing by 210 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_a5a6d00c400f510cLeak Siteblacklockfiled 2024-09-19(74d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_731343f80ce69f14Montana State AGfiled 2024-12-03Verified
- bd_ea699e36923736e3Maine State AGfiled 2024-12-03Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-12-03-new-river-electrical-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 3, 2024
- Raw hash
- b81a6b5481a8912b30a1bad1f090de8d040c55fdf35cb4dea6b79408df725866
Reporting entity
- Name
- New River Electrical Corp.norm: new river electrical
- Domain
- nrec.net
Victim entity
- Name
- New River Electrical Corp.norm: new river electrical
- Domain
- nrec.net
Incident
- Discovered
- May 6, 2024
- Materiality determined
- —
- Notification sent
- Dec 3, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported event to federal law enforcement
Compliance
- Time to disclose
- 30 weeks(211 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.