MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_BASICLowContained
ARPIN INTERNATIONAL GROUP, INC.
bd_8005f6d186336646 · schema v1 · pii pii-v1
Full breach record for ARPIN INTERNATIONAL GROUP, INC. →Arpin International Group, Inc. notified consumers of a ransomware attack discovered on April 14, 2023. Unauthorized access to files resulted in the potential exposure of names and other data elements. The company engaged forensic specialists, reported to federal law enforcement, and offered 12 months of Kroll identity monitoring. A secondary data set was identified later, with notifications sent in May 2024.
Vermont clock✗ VT AG >45 bday13 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-03-arpin-international-group-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 3, 2024
- Raw hash
- 9a5bc20c86ea431fd8098e1893461e3c0f35f639af20efcba599e9ab626f5bb5
Reporting entity
- Name
- ARPIN INTERNATIONAL GROUP, INC.norm: arpin international
Victim entity
- Name
- ARPIN INTERNATIONAL GROUP, INC.norm: arpin international
Incident
- Discovered
- Apr 14, 2023
- Materiality determined
- May 3, 2024
- Notification sent
- May 3, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported incident to federal law enforcement
Compliance
- Time to disclose
- 13 months(385 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.