HackingStolen CredentialsCapture Stored DataData ExfiltratedIDENTITY_BASICPIILowContained
Builders Insurance (A Mutual Captive Company)
bd_aa63b02d952af452 · schema v1 · pii pii-v1
Full breach record for Builders Insurance (A Mutual Captive Company) →Builders Mutual Insurance Company, Inc. notified consumers of a data breach discovered on December 14, 2022. Unauthorized access to its network occurred, resulting in the copying of files containing names and other personal information. The company reported the incident to law enforcement, implemented additional safeguards, and offered credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday41 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_00e6bd7a5cc86b96Maine State AGfiled 2023-09-29Candidate
- bd_7d6454372ca3b644New Hampshire State AGfiled 2023-09-29Verified
- bd_ab2cf2fa582e4a20Montana State AGfiled 2023-09-29Verified by operator
- bd_3054d507945b1361New Hampshire State AGfiled 2023-10-19(20d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-09-29-builders-mutual-insurance-company-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 29, 2023
- Raw hash
- 53543752413b0b5bce305f090a4b31ba9ab16e5f92b97ba9593f9c67538bd987
Reporting entity
- Name
- Builders Insurance (A Mutual Captive Company)norm: builders insurance a mutual captive
Victim entity
- Name
- Builders Insurance (A Mutual Captive Company)norm: builders insurance a mutual captive
Incident
- Discovered
- Dec 14, 2022
- Materiality determined
- Sep 29, 2023
- Notification sent
- Sep 29, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported this incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 41 weeks(289 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.