Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
National Advisors Holdings, Inc.
bd_a4171eab7b34e026 · schema v1 · pii pii-v1
Full breach record for National Advisors Holdings, Inc. →National Advisors Trust notified consumers of a data breach where an unauthorized individual accessed employee email accounts containing client information. The incident was discovered on April 17, 2023, following suspicious emails sent from an employee account. Affected data likely included names and other PII. NAT engaged forensic experts and offered credit monitoring services.
Vermont clock✗ VT AG >45 bday42 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_362afe212a144aa4California State AGfiled 2024-02-02Candidate
- bd_9e4aa5bc8400fae0New Hampshire State AGfiled 2024-02-02Verified
- bd_d555f6fe1556826bMontana State AGfiled 2024-02-02Verified
- bd_d55a09a6ca6cfaaeIndiana State AGfiled 2024-02-02Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_fb37ca7ea03711c6Maine State AGfiled 2024-02-03(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-02-02-national-advisors-holdings-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 2, 2024
- Raw hash
- 734968b937cb18a8502f714364cb42fad47f2ad9c23d299d0ec606e20defdbdb
Reporting entity
- Name
- National Advisors Holdings, Inc.norm: national advisors
Victim entity
- Name
- National Advisors Holdings, Inc.norm: national advisors
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- Feb 2, 2024
- Notification sent
- Jan 11, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified necessary regulatory agencies as required under applicable state and federal law
- Initial access
- phishing_link
Compliance
- Time to disclose
- 42 weeks(291 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.