Social EngineeringPhishingDelayed DiscoveryPIICREDENTIALSLowContained
Ellis Medicine
bd_857dcf594b69322b · schema v1 · pii pii-v1
Full breach record for Ellis Medicine →Ellis Medicine notified consumers of unauthorized access to an employee email account between Jan 17 and Apr 5, 2025. The incident involved suspicious activity likely stemming from phishing. Affected data included names and other data elements. Ellis Medicine reset credentials, engaged forensic specialists, and offered 12 months of credit monitoring.
Vermont clock✗ VT AG >45 bday27 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_fbd9cdca777dc587Maine State AGfiled 2025-07-22Candidate
- bd_c92ff11a81b2e709Indiana State AGfiled 2025-07-17(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-22-ellis-medicine-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2025
- Raw hash
- 4a88c6eea9805a15997ec5be4099f1738d3eb4b59cadb621f16c9c92824a71c2
Reporting entity
- Name
- Ellis Medicinenorm: ellis medicine
- Domain
- ellismedicine.org
Victim entity
- Name
- Ellis Medicinenorm: ellis medicine
- Domain
- ellismedicine.org
Incident
- Discovered
- Jan 17, 2025
- Materiality determined
- —
- Notification sent
- Jul 22, 2025
- Affected individuals
- Not disclosed
- Data types
- PIICREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 weeks(186 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.