HackingData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHICREDENTIALSMediumContained
Rockrose Development
bd_8f67a2bc7c1abe0e · schema v1 · pii pii-v1
Full breach record for Rockrose Development →Rockrose Development L.L.C. notified consumers of a security incident where unauthorized individuals accessed systems and acquired confidential information. Impacted data may include names, SSNs, tax IDs, driver's licenses, passport numbers, bank account/routing numbers, health insurance info, medical info, and online account credentials. Rockrose engaged third-party experts, secured systems, and offers 24 months of Experian IdentityWorks.
Leak gap clock⏱ Leak >90d≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 6 about the same incident.View merged incident
A leak claim by play about this victim predates this filing by 161 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_327fd30fe6daab6cNew Hampshire State AGfiled 2025-12-12Verified
- bd_75178716da4cecffIndiana State AGfiled 2025-12-12Verified
- bd_b356f77ac2799858Maine State AGfiled 2025-12-12Candidate
- bd_d9ccc4ea910fc347Texas State AGfiled 2025-12-12Verified
Show 1 more filing ↓Show fewer ↑
- bd_dd2409a79ea59245California State AGfiled 2025-12-12Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-12-rockrose-development-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2025
- Raw hash
- 9c7267361603fa11c403243531872a67e9a921bfb6b1835692401dcd53635806
Reporting entity
- Name
- Rockrose Developmentnorm: rockrose development
- Domain
- rockrose.com
Victim entity
- Name
- Rockrose Developmentnorm: rockrose development
- Domain
- rockrose.com
Incident
- Discovered
- Dec 12, 2025
- Materiality determined
- —
- Notification sent
- Dec 12, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHICREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- Leak >90dVT AG ≤14 bday
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.