HackingTargetedIDENTITY_BASICLowContained
Central Vermont Regional Planning Commission
bd_cd8cccf998f57eaa · schema v1 · pii pii-v1
Full breach record for Central Vermont Regional Planning Commission →Central Vermont Regional Planning Commission (CVRPC) notified consumers of a security incident on September 14, 2023, where an unauthorized party accessed its network server. CVRPC closed external network access, reviewed logs, and replaced vulnerable hardware. No evidence of data misuse was found. CVRPC offered 24 months of identity theft protection services through IDX to affected individuals.
Vermont clock⏱ VT AG >14 bday21 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-05-central-vermont-regional-planning-commission-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 5, 2023
- Raw hash
- fa762d38022de24c340f05c06746211abbe5fe77e45cc4725a722bc4c179a9c9
Reporting entity
- Name
- Central Vermont Regional Planning Commissionnorm: central vermont regional planning commission
- Domain
- cvregion.com
Victim entity
- Name
- Central Vermont Regional Planning Commissionnorm: central vermont regional planning commission
- Domain
- cvregion.com
Incident
- Discovered
- Sep 14, 2023
- Materiality determined
- —
- Notification sent
- Oct 5, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.