HackingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Conner Strong & Buckelew Companies, LLC
bd_84a012827c3ac59a · schema v1 · pii pii-v1
Full breach record for Conner Strong & Buckelew Companies, LLC →Conner Strong & Buckelew notified consumers of unauthorized access to certain employee email accounts between Feb 7 and Mar 30, 2022. The incident may have exposed personal information of clients. The firm engaged forensic investigators, reset passwords, and offered 12 months of credit monitoring through Experian.
Vermont clock✗ VT AG >45 bday17 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_cfddcf7d70714287Montana State AGfiled 2023-06-26Candidate
- bd_a52999f673a4fb4eVermont State AGfiled 2023-05-10(47d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-06-26-conner-strong-buckelew-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2023
- Raw hash
- ad1d9a58c14001e718603b3a3c276793482f35208ae9b56f6e8066e0d11ef600
Reporting entity
- Name
- Conner Strong & Buckelew Companies, LLCnorm: conner strong buckelew companies
Victim entity
- Name
- Conner Strong & Buckelew Companies, LLCnorm: conner strong buckelew companies
Incident
- Discovered
- Feb 7, 2022
- Materiality determined
- —
- Notification sent
- Jun 26, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- notified appropriate state and federal regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 months(504 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.