Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Williams Hart & Boundas LLP
bd_be1ce8a3e21067c7 · schema v1 · pii pii-v1
Full breach record for Williams Hart & Boundas LLP →Williams Hart & Boundas, LLP notified consumers of a phishing incident discovered on June 30, 2025, where an unauthorized individual accessed a firm email account. The breach exposed names, addresses, financial account numbers, driver's license numbers, SSNs, and health information. The firm engaged security experts, reset passwords, notified law enforcement, and offered credit monitoring.
Vermont clock✗ VT AG >45 bday15 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_21d84c8d5f9d1caeNew Hampshire State AGfiled 2025-10-09(4d gap)Verified
- bd_8aca3b6fa35c5edbMaine State AGfiled 2025-10-09(4d gap)Verified
- bd_6e5425fc35eec9ccTexas State AGfiled 2025-09-22(21d gap)Verified
- bd_387dcfeb85167badMontana State AGfiled 2025-09-19(24d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 24d gap
- bd_ae49906292b990c4Indiana State AGfiled 2025-09-19(24d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-10-13-williams-hart-boundas-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 13, 2025
- Raw hash
- 5c3adcd8a98f2c712c06d9b4680e4d2741569f29d71d17a7025eb6133d66555e
Reporting entity
- Name
- Williams Hart & Boundas LLPnorm: williams hart boundas
Victim entity
- Name
- Williams Hart & Boundas LLPnorm: williams hart boundas
Incident
- Discovered
- Jun 30, 2025
- Materiality determined
- —
- Notification sent
- Sep 19, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- promptly notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 15 weeks(105 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.