MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASICMediumContained
Beaver Run Resort & Conference Center
bd_9f2c51ee4bf0f0c3 · schema v1 · pii pii-v1
Full breach record for Beaver Run Resort & Conference Center →Beaver Run Resort & Conference Center notified Vermont AG of a ransomware incident discovered Feb 19, 2024. Unauthorized access occurred Feb 6-19, 2024, resulting in data encryption and exfiltration of SSNs, driver's licenses, passport numbers, and financial account info. The company engaged third-party specialists, restored systems, and offered 24 months of Experian identity monitoring. One Rhode Island resident was identified as potentially affected.
Vermont clock✗ VT AG >45 bday12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2d685f4c71e70b06Indiana State AGfiled 2024-05-16Verified
- bd_4be157dea328abbfMaine State AGfiled 2024-05-16Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-16-beaver-run-resort-conference-center-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 16, 2024
- Raw hash
- 31b7dc92c0850eab0f9547f351ce1499666f460d21c9e6df2113f98cca24231a
Reporting entity
- Name
- Beaver Run Resort & Conference Centernorm: beaver run resort conference center
Victim entity
- Name
- Beaver Run Resort & Conference Centernorm: beaver run resort conference center
Incident
- Discovered
- Feb 19, 2024
- Materiality determined
- May 16, 2024
- Notification sent
- May 16, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
Compliance
- Time to disclose
- 12 weeks(87 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.