MalwareRansomwareCapture Stored DataData ExfiltratedData EncryptedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENTMediumContained
ELEVATE SERVICES, INC.
bd_81a5900cdfa52331 · schema v1 · pii pii-v1
Full breach record for ELEVATE SERVICES, INC. →Elevate Services, Inc. notified consumers of a March 2022 ransomware incident where malicious file encryption rendered systems inaccessible. An unknown actor accessed and downloaded files between March 5-15, 2022. Impacted data included names, SSNs, driver's licenses, medical history, and employment info. Elevate engaged law enforcement, enhanced security processes, and offered 12 months of credit monitoring via Kroll.
Vermont clock✗ VT AG >45 bday50 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
A leak claim by conti about this victim predates this filing by 322 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_aa0ea316c8a8bac6Leak Sitecontifiled 2022-04-14(322d gap)Verified by operator
Regulatory filings (4) · sorted by filing gap
- bd_a3856ba06272067dCalifornia State AGfiled 2023-03-07(5d gap)Verified by operator
- bd_a48b2854bfc15412Montana State AGfiled 2023-02-08(22d gap)Verified by operator
- bd_5ce595d1266de680Montana State AGfiled 2023-04-19(48d gap)Verified by operator
- bd_974c9c80d6c62aebCalifornia State AGfiled 2022-12-28(64d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-03-02-elevate-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2023
- Raw hash
- a1747891e1cd3b30bebb05eab5abd90d459e1eca0be04630761d527eeed373bf
Reporting entity
- Name
- ELEVATE SERVICES, INC.norm: elevate services
Victim entity
- Name
- ELEVATE SERVICES, INC.norm: elevate services
Incident
- Discovered
- Mar 14, 2022
- Materiality determined
- —
- Notification sent
- Mar 2, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement
Compliance
- Time to disclose
- 50 weeks(353 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.