HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
North Atlantic States Carpenters Benefit Funds
bd_ef203187ce86e64f · schema v1 · pii pii-v1
Full breach record for North Atlantic States Carpenters Benefit Funds →North Atlantic States Carpenters Benefit Funds (NASCBF) notified consumers of a data breach occurring on August 18, 2025, involving unauthorized access to its Hamden, CT office network. The incident may have exposed names and government identifiers. NASCBF reset passwords, engaged forensic investigators, notified law enforcement, and is offering complimentary credit monitoring through Epiq.
Vermont clock✗ VT AG >45 bday25 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_26ca88c6d91bab3eNew Hampshire State AGfiled 2026-02-11Verified
- bd_7d0152cd19d54aa8Maine State AGfiled 2026-02-11Candidate
- bd_aa7d90f26edd4702Indiana State AGfiled 2026-02-11Verified by operator
- bd_823e1bfd6c35b5bfTexas State AGfiled 2026-02-13(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-11-north-atlantic-states-carpenters-benefit-funds-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 11, 2026
- Raw hash
- afd225098758b5d82674b82836b054324156f5ccf8c606dfd19fee4f3c075945
Reporting entity
- Name
- North Atlantic States Carpenters Benefit Fundsnorm: north atlantic states carpenters benefit funds
- Domain
- carpentersfund.org
Victim entity
- Name
- North Atlantic States Carpenters Benefit Fundsnorm: north atlantic states carpenters benefit funds
- Domain
- carpentersfund.org
Incident
- Discovered
- Aug 18, 2025
- Materiality determined
- —
- Notification sent
- Feb 11, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified law enforcementwill notify appropriate state and federal regulators, as required
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(177 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.