HackingStolen CredentialsDelayed DiscoveryData ExfiltratedPIIIDENTITY_BASICLowContained
HENNESSY ADVISORS, INC.
bd_d11bdc8476440748 · schema v1 · pii pii-v1
Full breach record for HENNESSY ADVISORS, INC. →Hennessy Advisors, Inc., an investment management firm, disclosed a data breach discovered on March 30, 2025. Unauthorized access to investor personal information occurred, with confirmation of data access in late December 2025. The firm retained third-party specialists and is offering credit monitoring and identity theft protection services to affected individuals.
Vermont clock✗ VT AG >45 bday47 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_155d62cf97956468Indiana State AGfiled 2026-02-23Candidate
- bd_072c9ab8534cfc81California State AGfiled 2026-02-24(1d gap)Verified
- bd_41991ab4574f8c98Maine State AGfiled 2026-02-24(1d gap)Verified by operator
- bd_6d4e4e25f72021c3New Hampshire State AGfiled 2026-02-24(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 2d gap
- bd_4a3d6923a18d23b5Texas State AGfiled 2026-02-25(2d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-23-hennessy-advisors-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2026
- Raw hash
- c98c693dd79fdd3a2a070974a02f0affc42cc2ed750c9c72fa7c3659c062b1a8
Reporting entity
- Name
- HENNESSY ADVISORS, INC.norm: hennessy advisors
- Domain
- hennessyadvisors.com
Victim entity
- Name
- HENNESSY ADVISORS, INC.norm: hennessy advisors
- Domain
- hennessyadvisors.com
Incident
- Discovered
- Mar 30, 2025
- Materiality determined
- Feb 23, 2026
- Notification sent
- Feb 23, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 47 weeks(330 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.