HackingPhishingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedMulti-Stage ChainIDENTITY_BASICCREDENTIALSPIILowActive
Butler Brothers Supply Division
bd_8cba134bdf9b4d39 · schema v1 · pii pii-v1
Full breach record for Butler Brothers Supply Division →Butler Brothers Supply Division notified consumers of a third-party data breach involving SignatureIT Ltd., its e-commerce platform provider. SignatureIT detected unauthorized access on November 16, 2023, following suspicious email activity. While Butler Brothers' internal systems were unaffected, user data stored on SignatureIT servers may have been accessed, including names, addresses, passwords, and transaction details. Butler Brothers notified the FBI, CISA, state agencies, and EU regulators.
Vermont clock✓ VT AG ≤14 bday20 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_d236eb6f2a18ce7eNew Hampshire State AGfiled 2023-12-14(8d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-06-butler-brothers-supply-division-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 6, 2023
- Raw hash
- 854789e5a4c1626647f879202f82192816209bd9959f93b391fe5cb8770a3f79
Reporting entity
- Name
- Butler Brothers Supply Divisionnorm: butler brothers supply division
- Domain
- butlerbros.com
Victim entity
- Name
- Butler Brothers Supply Divisionnorm: butler brothers supply division
- Domain
- butlerbros.com
Incident
- Discovered
- Nov 16, 2023
- Materiality determined
- —
- Notification sent
- Dec 6, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALSPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified the U.S. Federal Bureau of InvestigationNotified the Cybersecurity and Infrastructure Security Agency under the Cyber Incident Reporting for Critical Infrastructure ActNotified applicable U.S. state agenciesNotified the E.U. under the General Data Protection Regulation
- Third party
- via SignatureIT Ltd.
- Initial access
- phishing_link
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.