HackingDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Frost & Sullivan
bd_f51afad63d17b41e · schema v1 · pii pii-v1
Full breach record for Frost & Sullivan →Frost & Sullivan, Inc. notified consumers of a cyber-attack discovered on July 8, 2023, which resulted in unauthorized access to systems containing current and former employees' names and Social Security numbers. The company implemented additional security measures and offered 24 months of complimentary credit monitoring via Experian IdentityWorks. The investigation was ongoing at the time of notification.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 39 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_184a8b1f0d889d98Montana State AGfiled 2023-09-05Candidate
- bd_407c587322cd8972New Hampshire State AGfiled 2023-09-05Verified
- bd_e4520694f1251272Maine State AGfiled 2023-09-05Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-09-05-frost-sullivan-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2023
- Raw hash
- d25b50486d27f187c359767bf49ef9017e07ad8ee7ae4e2a988c6a4c12b42b8b
Reporting entity
- Name
- Frost & Sullivannorm: frost sullivan
- Domain
- frost.com
Victim entity
- Name
- Frost & Sullivannorm: frost sullivan
- Domain
- frost.com
Incident
- Discovered
- Jul 8, 2023
- Materiality determined
- Sep 5, 2023
- Notification sent
- Sep 5, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- VT AG >14 bdayLeak >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.