DisclosureLens
AccidentalFinancial ServicesFinanceMisconfigurationSupply Chain (3P Vendor)Data ExfiltratedIdentity (basic)Government IDFinancial accountMediumContained

New England Risk Management, Inc.

bd_93ff985667e90d1c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jun 22, 2021

To disclose

Affected

Not disclosed

Confidence

64%

New England Risk Management, Inc. notified the NH Attorney General of a data breach involving its third-party vendor Vertafore. A configuration error in Vertafore's QQCatalyst product (existing 2012-2020) allowed unauthorized public access to reports and forms. Impacted data included names, addresses, birthdates, driver's license numbers, and potentially SSNs and financial account info. Vertafore fixed the error, engaged forensic investigators, and offered 1 year of credit monitoring.

Incident timeline

Jan 1, 2012

Begins

Jun 22, 2021

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.