Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICCREDENTIALSLowContained
Conner Strong & Buckelew Companies, LLC
bd_a52999f673a4fb4e · schema v1 · pii pii-v1
Full breach record for Conner Strong & Buckelew Companies, LLC →Conner Strong & Buckelew Companies notified consumers of a data breach involving unauthorized access to employee email accounts between Feb 7 and Mar 30, 2022. The incident resulted from phishing leading to credential compromise. Personal information of clients was accessed. CSB reset passwords, engaged forensic investigators, and notified regulators. No specific count of affected individuals was disclosed.
Vermont clock✗ VT AG >45 bday15 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_84a012827c3ac59aVermont State AGfiled 2023-06-26(47d gap)Verified
- bd_cfddcf7d70714287Montana State AGfiled 2023-06-26(47d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-05-10-conner-strong-buckelew-companies-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 10, 2023
- Raw hash
- f0bac55c1d3ea5d7be0cbc78228bdd080748095d3a163325b0e11a23fddccb40
Reporting entity
- Name
- Conner Strong & Buckelew Companies, LLCnorm: conner strong buckelew companies
Victim entity
- Name
- Conner Strong & Buckelew Companies, LLCnorm: conner strong buckelew companies
Incident
- Discovered
- Feb 7, 2022
- Materiality determined
- May 10, 2023
- Notification sent
- May 10, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified appropriate state and federal regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 15 months(457 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.