MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_BASICLowContained
Harwood Lloyd, LLP
bd_c7f3e64cbd0ab20f · schema v1 · pii pii-v1
Full breach record for Harwood Lloyd, LLP →Harwood Lloyd, LLP notified consumers of a data breach occurring April 16-21, 2023. An unauthorized third party accessed systems, encrypted files, and exfiltrated personal information including names. The firm engaged forensic investigators and law enforcement, enhanced security measures, and offered one year of Experian IdentityWorks credit monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday19 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 522 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_402c63010edc4ad5Montana State AGfiled 2024-11-05Candidate
- bd_95fcfcaf4185dc59Maine State AGfiled 2024-11-05Verified by operator
- bd_c5f8c1c7c64405c2New Hampshire State AGfiled 2024-11-05Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-11-05-harwood-lloyd-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 5, 2024
- Raw hash
- 08f9fb2028be53c0a27186592ff891173de2e3aa1d61606e54af6d9d1150a970
Reporting entity
- Name
- Harwood Lloyd, LLPnorm: harwood lloyd
- Domain
- harwoodlloyd.com
Victim entity
- Name
- Harwood Lloyd, LLPnorm: harwood lloyd
- Domain
- harwoodlloyd.com
Incident
- Discovered
- Apr 16, 2023
- Materiality determined
- Oct 10, 2023
- Notification sent
- Nov 5, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 19 months(569 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.