Social EngineeringPhishingStolen CredentialsTargetedIDENTITY_BASICCREDENTIALSLowContained
Integral Federal Inc.
bd_9ba8ae660b6b5a7d · schema v1 · pii pii-v1
Full breach record for Integral Federal Inc. →Integral Federal Inc. notified consumers in Vermont and other states that between Feb 11 and Mar 30, 2023, an unauthorized actor accessed employee email accounts via suspicious activity (likely phishing). The incident may have exposed names and email addresses. Integral Federal secured accounts, investigated, and offered 24 months of credit monitoring.
Vermont clock✗ VT AG >45 bday16 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_196c2761a331dbabVermont State AGfiled 2024-04-25(69d gap)Verified
- bd_28ad276a2b83a969Indiana State AGfiled 2024-04-25(69d gap)Verified
- bd_612f0c0ada1d2710Montana State AGfiled 2024-04-25(69d gap)Candidate
- bd_82625411e9315de1Maine State AGfiled 2024-04-25(69d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 69d gap
- bd_bae8f3126052e2b8New Hampshire State AGfiled 2024-04-25(69d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-07-03-integral-federal-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2024
- Raw hash
- 70e02bef0329bb859eb66424d432e6192a3ed85d01c10de1c431f9b0690c2a8b
Reporting entity
- Name
- Integral Federal Inc.norm: integral federal
Victim entity
- Name
- Integral Federal Inc.norm: integral federal
Incident
- Discovered
- Mar 24, 2023
- Materiality determined
- —
- Notification sent
- Jul 3, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- notifying state regulators, as required
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 months(467 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.