MalwareRansomwareData EncryptedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Waterborne Environmental
bd_a37606a54468c0f5 · schema v1 · pii pii-v1
Full breach record for Waterborne Environmental →Waterborne Environmental, Inc. disclosed a ransomware incident detected on September 21, 2025. The attack impacted personal information including names, DOBs, SSNs, driver's licenses, and health insurance numbers. The company engaged forensic experts, cooperated with the FBI and CISA, and offered credit monitoring services. No specific affected individual count was provided in the filing.
Vermont clock✗ VT AG >45 bday9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by play about this victim predates this filing by 630 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_b01c39d4b58d02deLeak Siteplayfiled 2025-09-18(69d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_636220fab0b7a7cdIndiana State AGfiled 2025-11-26Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-26-waterborne-environmental-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 26, 2025
- Raw hash
- db67b8a7ab5c278f9ff44fa9c081437abe1a437b18d43121f3a0ffa8119dffeb
Reporting entity
- Name
- Waterborne Environmentalnorm: waterborne environmental
- Domain
- waterborne-env.com
Victim entity
- Name
- Waterborne Environmentalnorm: waterborne environmental
- Domain
- waterborne-env.com
Incident
- Discovered
- Sep 21, 2025
- Materiality determined
- Nov 26, 2025
- Notification sent
- Nov 26, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Cooperating with FBI’s Cyber Crimes DivisionCooperating with the Homeland Security Cybersecurity and Infrastructure Security Agency
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.