HackingStolen CredentialsData ExfiltratedTargetedIDENTITY_BASICLowContained
Kisco Senior Living
bd_ae5fc063c5610e63 · schema v1 · pii pii-v1
Full breach record for Kisco Senior Living →Kisco Senior Living, LLC experienced a data security incident on June 6, 2023, where files were acquired without authorization. The breach may have involved personal information including names. Kisco engaged cybersecurity experts, notified the FBI, and offered complimentary credit monitoring and identity protection services to affected individuals.
Vermont clock✗ VT AG >45 bday45 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by blackbyte about this victim predates this filing by 306 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_97e4a4804c5982e4Leak Siteblackbytefiled 2023-06-16(306d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_af958651b75c8f51Montana State AGfiled 2024-04-17Verified by operator
- bd_2f2ae62c22792441California State AGfiled 2024-04-18(1d gap)Verified
- bd_bf4a8afa6c1d0153Maine State AGfiled 2024-04-19(2d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-17-kisco-senior-living-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 17, 2024
- Raw hash
- ff7b22b2077a4b7100a8c17afeb9578f94dd766ee680236239446958f58a4f67
Reporting entity
- Name
- Kisco Senior Livingnorm: kisco senior living
- Domain
- kiscoseniorliving.com
Victim entity
- Name
- Kisco Senior Livingnorm: kisco senior living
- Domain
- kiscoseniorliving.com
Incident
- Discovered
- Jun 6, 2023
- Materiality determined
- Apr 9, 2024
- Notification sent
- Apr 16, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 45 weeks(316 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.