HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIMediumContained
Community Realty Management
bd_c60bf182d56a5937 · schema v1 · pii pii-v1
Full breach record for Community Realty Management →Community Realty Management, Inc. disclosed unauthorized access to a limited number of email accounts between September 10, 2024, and October 22, 2024. The incident exposed names, state IDs, SSNs, financial account info, and health insurance data. The company engaged third-party forensic specialists, secured systems, and is offering 12 months of credit monitoring. No specific individual count was disclosed in the filing.
Vermont clock✗ VT AG >45 bday48 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_8862916b17daeb45Maine State AGfiled 2025-08-12Verified
- bd_83b50ce91950ee9fNew Hampshire State AGfiled 2025-08-11(1d gap)Verified
- bd_d534bf7b50477212Indiana State AGfiled 2025-08-11(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-08-12-community-realty-management-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 12, 2025
- Raw hash
- b7129a8b3f3fe58fba00ee70c7fd54f1898e0eaecc69b37a118c630b981b9f8a
Reporting entity
- Name
- Community Realty Managementnorm: community realty management
Victim entity
- Name
- Community Realty Managementnorm: community realty management
Incident
- Discovered
- Sep 10, 2024
- Materiality determined
- Aug 11, 2025
- Notification sent
- Aug 11, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 48 weeks(336 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.