Social EngineeringPhishingTargetedIDENTITY_BASICLowContained
Rkl LLP
bd_98f8a7a5e33cfaef · schema v1 · pii pii-v1
Full breach record for Rkl LLP →RKL, LLP notified consumers of a phishing incident where an employee's email account was accessed without authorization between May 11 and June 19, 2023. The incident involved access to names and email addresses. RKL secured the account, offered credit monitoring, and enhanced security training.
Vermont clock✗ VT AG >45 bday33 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-28-rkl-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 28, 2023
- Raw hash
- 7ca3481460c01fbc8084ed7322019953869d0261218e0f45286f45e81667540a
Reporting entity
- Name
- Rkl LLPnorm: rkl
Victim entity
- Name
- Rkl LLPnorm: rkl
Incident
- Discovered
- May 11, 2023
- Materiality determined
- —
- Notification sent
- Dec 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notifying relevant regulatory authorities
- Initial access
- phishing_link
Compliance
- Time to disclose
- 33 weeks(231 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.