HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The Mike Ferry Organization
bd_b698f7cc5f1fb5ac · schema v1 · pii pii-v1
Full breach record for The Mike Ferry Organization →The Mike Ferry Organization notified consumers of a cybersecurity incident on December 18, 2023, where an unauthorized party gained access to its network. The investigation revealed that names and Social Security Numbers may have been exposed. MFO engaged forensic investigators, secured the network, and is offering 12 months of credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday17 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1dcb05e551310f1cIndiana State AGfiled 2024-04-16(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-15-mike-ferry-organization-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 15, 2024
- Raw hash
- da80ec7af65aeca6124c53c1a96b96f8b252a451853f2547e0f0c954db055e12
Reporting entity
- Name
- The Mike Ferry Organizationnorm: the mike ferry organization
Victim entity
- Name
- The Mike Ferry Organizationnorm: the mike ferry organization
Incident
- Discovered
- Dec 18, 2023
- Materiality determined
- Apr 15, 2024
- Notification sent
- Apr 15, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.