HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Georgetown Brewing Company
bd_c62af42c4d23d1a2 · schema v1 · pii pii-v1
Full breach record for Georgetown Brewing Company →Georgetown Brewing Company notified Vermont consumers of a data breach discovered on August 22, 2025. A threat actor gained unauthorized access to servers and exfiltrated names and driver's license numbers. No SSN or financial data was impacted. The company reported the incident to law enforcement and is offering IDX identity theft protection services.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by inc_ransom about this victim predates this filing by 35 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_e7b83d97438da500Leak Siteinc_ransomfiled 2025-08-22(35d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_44441ed00e966a82Maine State AGfiled 2025-09-26Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-09-26-georgetown-brewing-company-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2025
- Raw hash
- 3120465c561f187e07fc37429c29951d89ff8b6084063e6f45c1b7cbc23935b5
Reporting entity
- Name
- Georgetown Brewing Companynorm: georgetown brewing
- Domain
- georgetownbeer.com
Victim entity
- Name
- Georgetown Brewing Companynorm: georgetown brewing
- Domain
- georgetownbeer.com
Incident
- Discovered
- Aug 22, 2025
- Materiality determined
- —
- Notification sent
- Sep 26, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- VT AG >14 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.