Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Knox McLaughlin Gornall & Sennett PC
bd_7d8ac106361b59de · schema v1 · pii pii-v1
Full breach record for Knox McLaughlin Gornall & Sennett PC →Knox McLaughlin Gornall & Sennett, P.C. notified consumers of a data security incident detected on May 14, 2025, involving suspicious activity in an employee's email account. Files containing personal information, including names, SSNs, driver's license numbers, and medical data, were accessed on May 19, 2025. The firm engaged cybersecurity specialists and is offering 12 months of credit monitoring and fraud assistance.
Vermont clock✗ VT AG >45 bday21 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_9dba301b3923e666Maine State AGfiled 2025-10-07Candidate
- bd_2d23f22a176fe23cNew Hampshire State AGfiled 2025-10-08(1d gap)Verified
- bd_d1c1c06c6d048481Montana State AGfiled 2025-10-08(1d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-10-07-knox-mclaughlin-gornall-sennett-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 7, 2025
- Raw hash
- e9455a10ab1cbbe8b48173beffffca3fd44e838806a74255772db220bbde4f7b
Reporting entity
- Name
- Knox McLaughlin Gornall & Sennett PCnorm: knox mclaughlin gornall sennett
Victim entity
- Name
- Knox McLaughlin Gornall & Sennett PCnorm: knox mclaughlin gornall sennett
Incident
- Discovered
- May 14, 2025
- Materiality determined
- —
- Notification sent
- Oct 7, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 weeks(146 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.