Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
Custom Wealth Management
bd_f9e1a392902a5c52 · schema v1 · pii pii-v1
Full breach record for Custom Wealth Management →Custom Wealth Management notified Vermont consumers of a data breach occurring around July 15, 2024. Unauthorized access to one individual's email mailbox was identified following suspicious activity. The incident may have exposed names and other personal information. No conclusive evidence of misuse was found. CWM engaged forensic reviewers and offered complimentary credit monitoring and identity protection services through IDX.
Vermont clock✗ VT AG >45 bday16 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_09dd5b74a5d73c13New Hampshire State AGfiled 2024-11-04Verified
- bd_eef63ca901f73304Indiana State AGfiled 2024-11-04Verified
- bd_f826ad9c0669f642Maine State AGfiled 2024-11-07(3d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-11-04-custom-wealth-management-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 4, 2024
- Raw hash
- 5a4f51f32dc9ffc0ebb63f8cb4918ff79db40333ed5c6f3725b5fcc737ecc703
Reporting entity
- Name
- Custom Wealth Managementnorm: custom wealth management
Victim entity
- Name
- Custom Wealth Managementnorm: custom wealth management
Incident
- Discovered
- Jul 15, 2024
- Materiality determined
- —
- Notification sent
- Nov 4, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.