HackingStolen CredentialsData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Southeast Vermont Transit, Inc.
bd_85b566b4f054af55 · schema v1 · pii pii-v1
Full breach record for Southeast Vermont Transit, Inc. →Southeast Vermont Transit (SEVT) notified consumers of a data security incident detected on December 7, 2023. Unauthorized access to SEVT's network resulted in the exposure of names, driver's license info, direct deposit info, Medicaid numbers, and Social Security numbers. SEVT engaged a third-party cybersecurity firm, disconnected network access, changed credentials, and offered 12 months of credit monitoring and fraud assistance.
Vermont clock✗ VT AG >45 bday13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_c60d39d0a0be2f93Maine State AGfiled 2024-03-08Candidate
- bd_2a8f16508d9ebcd0New Hampshire State AGfiled 2024-03-11(3d gap)Verified
- bd_196ca05c2532e121New Hampshire State AGfiled 2024-04-29(52d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-03-08-southeast-vermont-transit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 8, 2024
- Raw hash
- ee4259e3d21efc6315606b11fbde36a4c1fcdce8076f334aea6dbe9910194e8a
Reporting entity
- Name
- Southeast Vermont Transit, Inc.norm: southeast vermont transit
Victim entity
- Name
- Southeast Vermont Transit, Inc.norm: southeast vermont transit
Incident
- Discovered
- Dec 7, 2023
- Materiality determined
- —
- Notification sent
- Mar 8, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(92 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.