Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICCREDENTIALSLowContained
National Advisors Holdings, Inc.
bd_e7d178d353d24dfd · schema v1 · pii pii-v1
Full breach record for National Advisors Holdings, Inc. →National Advisors Trust notified consumers of a data breach where an employee's email account was compromised via phishing. Unauthorized access to four employee email accounts exposed client names and other personal information. Forensic experts were engaged, and notifications were sent in waves starting February 2024. No evidence of data misuse was found.
Vermont clock✗ VT AG >45 bday16 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8bb50356ed20fe23Maine State AGfiled 2024-08-13(1d gap)Candidate
- bd_2aff28697cf02eb2New Hampshire State AGfiled 2024-08-12(2d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-08-14-national-advisors-holdings-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2024
- Raw hash
- 803f25f4254a351d08f4fb37883e6b2b59a02a7882c7b4923b53f7c17f44aac1
Reporting entity
- Name
- National Advisors Holdings, Inc.norm: national advisors
Victim entity
- Name
- National Advisors Holdings, Inc.norm: national advisors
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- Feb 2, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified regulatory agencies as required under applicable state and federal law
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 months(485 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.