MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_BASICHEALTH_BASICLowContained
PurFoods Holdings, LLC
bd_e470432f0b0b5928 · schema v1 · pii pii-v1
Full breach record for PurFoods Holdings, LLC →PurFoods, LLC notified consumers of a cyberattack occurring between Jan 16 and Feb 22, 2023. The incident involved file encryption and potential data exfiltration. Affected data included names and health insurance member IDs. PurFoods engaged third-party specialists, notified federal law enforcement, and offered 12 months of credit monitoring via Kroll.
Vermont clock✗ VT AG >45 bday26 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_5922a07dfc32ec37Maine State AGfiled 2023-08-25Verified
- bd_71f79a87b2334fa2New Hampshire State AGfiled 2023-08-25Verified
- bd_c2d1d182956f3f11Montana State AGfiled 2023-08-25Candidate
- bd_d13fdb19999e965eCalifornia State AGfiled 2023-08-25Verified
Show 2 more filings ↓Show fewer ↑up to 6d gap
- bd_eaf838850645f5a2Washington State AGfiled 2023-08-25Verified
- bd_b19ff7b969be846dOregon State AGfiled 2023-08-31(6d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-25-purfoods-holdings-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2023
- Raw hash
- ceb8bad844c30cf400976947b9753b92f40d58b32a229f93679097d04e0d0b9d
Reporting entity
- Name
- PurFoods Holdings, LLCnorm: purfoods holdings
Victim entity
- Name
- PurFoods Holdings, LLCnorm: purfoods holdings
Incident
- Discovered
- Feb 22, 2023
- Materiality determined
- —
- Notification sent
- Aug 25, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Federal law enforcement
Compliance
- Time to disclose
- 26 weeks(184 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.