HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Jeffries Morris
bd_d776755ddd8be20f · schema v1 · pii pii-v1
Full breach record for Jeffries Morris →Jeffries Morris, Inc. disclosed unauthorized access to its network on or about January 20, 2023. The incident compromised names and Social Security numbers of affected individuals. JMI engaged third-party forensic specialists, isolated systems, and notified regulators. The company offered complimentary credit and identity monitoring via Experian to affected consumers.
Vermont clock✗ VT AG >45 bday16 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
A leak claim by ransomhouse about this victim predates this filing by 91 days.View originating leak claim
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-05-11-jeffries-morris-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 11, 2023
- Raw hash
- d17e609af6281d8185765eb23fc86e6f3f8ec2273859c3523f30073678b25299
Reporting entity
- Name
- Jeffries Morrisnorm: jeffries morris
- Domain
- thejeffriescompanies.com
Victim entity
- Name
- Jeffries Morrisnorm: jeffries morris
- Domain
- thejeffriescompanies.com
Incident
- Discovered
- Jan 20, 2023
- Materiality determined
- —
- Notification sent
- May 11, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notifying relevant regulators as required
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.