HackingDelayed DiscoveryIDENTITY_BASICOTHERLowContained
Cabot Risk Strategies, LLC
bd_f7a2132520b8e990 · schema v1 · pii pii-v1
Full breach record for Cabot Risk Strategies, LLC →Cabot Risk Strategies, LLC notified consumers of a data security incident where unauthorized access occurred on April 24, 2023. The breach affected names and variable data. 27 Vermont residents were explicitly identified as impacted. Cabot engaged forensic specialists and offered 24 months of identity theft protection.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_5c99c056cd275015New Hampshire State AGfiled 2023-07-26Verified
- bd_75caa8318a907dbeMontana State AGfiled 2023-07-26Candidate
- bd_ef022000d5c0b51cMaine State AGfiled 2023-07-26Candidate
- bd_f293c84e1bcd3059Vermont State AGfiled 2023-08-22(27d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 28d gap
- bd_171d0f19dd19cbf5New Hampshire State AGfiled 2023-08-23(28d gap)Candidate
- bd_2069dae48c53e71dMaine State AGfiled 2023-08-23(28d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-26-cabot-risk-strategies-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2023
- Raw hash
- 492bf9052fe5f16e834f330fdc0f123ee18630f804b01bfe636b6b4b268e5eb5
Reporting entity
- Name
- Cabot Risk Strategies, LLCnorm: cabot risk strategies
- Domain
- cabotrisk.com
Victim entity
- Name
- Cabot Risk Strategies, LLCnorm: cabot risk strategies
- Domain
- cabotrisk.com
Incident
- Discovered
- May 10, 2023
- Materiality determined
- Jul 26, 2023
- Notification sent
- Jul 26, 2023
- Affected individuals
- 27
- Data types
- IDENTITY_BASICOTHER
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.