HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
40 Austin Associates, LLC
bd_c4ac9be5315170fb · schema v1 · pii pii-v1
Full breach record for 40 Austin Associates, LLC →Austin Associates, P.A. experienced unauthorized access to its computer environment from Feb 26 to Mar 17, 2025. An unknown third party obtained access to personal information including names, addresses, and government IDs. The company engaged third-party specialists, notified law enforcement and regulators, and offered credit monitoring services. The incident status is contained.
Vermont clock✗ VT AG >45 bday44 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-31-bdmpa-llc-dba-austin-associates-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 31, 2025
- Raw hash
- 729df2fb0de31cf4103e72b1b8bcacb20d41d4fa6eef2aee5dc3127d17e4f3c4
Reporting entity
- Name
- BDMPA LLCnorm: bdmpa
- Domain
- austinpa.com
Victim entity
- Name
- 40 Austin Associates, LLCnorm: 40 austin associates
Incident
- Discovered
- Feb 26, 2025
- Materiality determined
- Dec 31, 2025
- Notification sent
- Dec 31, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notifying relevant state regulatorsReported this incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 44 weeks(308 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.