Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
VUC, Inc.
bd_eaa38fc0d70c5fa3 · schema v1 · pii pii-v1
Full breach record for VUC, Inc. →VUC, Inc. notified the Maryland AG of a data event affecting 2 Maryland residents. Suspicious activity on an employee email account was detected on Oct 16, 2024, following unauthorized access between Oct 10-16, 2024. Names and SSNs were potentially accessed. VUC secured the email tenant, investigated, and offered 12 months of credit monitoring.
Maryland clock✗ MD AG >90d22 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_436ee5c25f8f512cVermont State AGfiled 2025-03-19(1d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376690.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 20, 2025
- Raw hash
- d9cb30ae7e6093ba4e3bd3733e76205c84a099ac6e27131b965b17b9a8dac50a
Reporting entity
- Name
- VUC, Inc.norm: vuc
Victim entity
- Name
- VUC, Inc.norm: vuc
Incident
- Discovered
- Oct 16, 2024
- Materiality determined
- —
- Notification sent
- Mar 19, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 22 weeks(155 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.