HackingStolen CredentialsTargetedPIIIDENTITY_BASICLowContained
Epi Breads
bd_8ac0d56e42cb9bfd · schema v1 · pii pii-v1
Full breach record for Epi Breads →EPI Breads notified Vermont AG of a data security incident discovered on August 22, 2024, involving unauthorized access to network systems. The investigation concluded on September 17, 2024, revealing that personal information, including names, was potentially accessed. EPI Breads engaged external cybersecurity experts, secured its network, and implemented additional safeguards. The company is offering 12 months of complimentary credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by play about this victim predates this filing by 75 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_95ecdef2bec3dbf8Maine State AGfiled 2024-11-04Candidate
- bd_dbf6b1a476086b89New Hampshire State AGfiled 2024-11-04Verified
- bd_78b7772be460e7b7Indiana State AGfiled 2024-10-30(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-11-04-epi-breads-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 4, 2024
- Raw hash
- 0234fdfa37b7607bb0b080c6702bc134ece083e32d171b4425699c33a2feeab4
Reporting entity
- Name
- Epi Breadsnorm: epi breads
- Domain
- epibreads.com
Victim entity
- Name
- Epi Breadsnorm: epi breads
- Domain
- epibreads.com
Incident
- Discovered
- Aug 22, 2024
- Materiality determined
- —
- Notification sent
- Oct 30, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.