HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedPIIPHIIDENTITY_BASICLowContained
SimonMed Imaging
bd_960fde2557f26bd7 · schema v1 · pii pii-v1
Full breach record for SimonMed Imaging →SimonMed Imaging reported a data breach affecting patients. A vendor alerted SimonMed on Jan 27, 2025, leading to discovery of unauthorized access between Jan 21 and Feb 5, 2025. The incident involved a third-party supply chain compromise. Affected data included names and other personal information. SimonMed engaged forensic professionals, reset passwords, enhanced MFA, and offered credit monitoring.
Vermont clock✗ VT AG >45 bday36 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 256 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_0d423abe97b4707fLeak Sitemedusafiled 2025-02-07(245d gap)Verified
- bd_d0b43d8c11131cf9Leak Sitemedusafiled 2025-01-27(256d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_0ccf1523fb1521c2California State AGfiled 2025-10-10Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-10-10-simonmed-imaging-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 10, 2025
- Raw hash
- 95a264cb2fc3d35a7e4954b7f9dd289d717fb9a0bf3eb836f4e6d3897eb282b5
Reporting entity
- Name
- SimonMed Imagingnorm: simonmed imaging
- Domain
- simonmed.com
Victim entity
- Name
- SimonMed Imagingnorm: simonmed imaging
- Domain
- simonmed.com
Incident
- Discovered
- Jan 28, 2025
- Materiality determined
- Oct 10, 2025
- Notification sent
- Oct 10, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported this Incident to relevant government agencies
- Initial access
- supply_chain
Compliance
- Time to disclose
- 36 weeks(255 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.