HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
Thompson & Horton LLP
bd_ca2da2865ef941c2 · schema v1 · pii pii-v1
Full breach record for Thompson & Horton LLP →Thompson & Horton, LLP notified consumers of a data breach affecting its managed IT services provider, All Covered. Unauthorized access occurred between April 13 and May 3, 2024. The incident involved the compromise of client names. The firm engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring. No evidence of misuse was found. The notice was filed with the Vermont Attorney General on October 29, 2025.
Vermont clock✗ VT AG >45 bday18 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_62dd0345ed0ce465Montana State AGfiled 2025-10-29Candidate
- bd_68dca34fb6031c4dNew Hampshire State AGfiled 2025-10-29Verified
- bd_b344e037d355f1a0Indiana State AGfiled 2025-10-29Verified
- bd_2460f839b22fc504Maine State AGfiled 2025-10-30(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_71c2bdcabc3a48a7Texas State AGfiled 2025-10-30(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-10-29-thompson-horton-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 29, 2025
- Raw hash
- 79684cb37c7762dbd26f10e3a122e20b461a3b3f0fe1ce1197bb16f12644fad3
Reporting entity
- Name
- Thompson & Horton LLPnorm: thompson horton
Victim entity
- Name
- Thompson & Horton LLPnorm: thompson horton
Incident
- Discovered
- May 3, 2024
- Materiality determined
- Oct 29, 2025
- Notification sent
- Oct 29, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Third party
- via All Covered
- Initial access
- supply_chain
Compliance
- Time to disclose
- 18 months(544 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.