HackingStolen CredentialsData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Legend Senior Living, LLC
bd_fdb466d7085a68c7 · schema v1 · pii pii-v1
Full breach record for Legend Senior Living, LLC →Legend Senior Living, LLC reported unauthorized access to systems affecting 4 Vermont residents between July 27 and August 15, 2025. Compromised data included names and Social Security numbers. The company notified law enforcement, offered 12 months of credit monitoring via TransUnion, and is reviewing security policies.
Vermont clock✗ VT AG >45 bday37 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by worldleaks about this victim predates this filing by 255 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_b7780c99023cd83cLeak Siteworldleaksfiled 2025-07-29(255d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_3b55cf33ba553be6Indiana State AGfiled 2026-04-10Candidate
- bd_82e727328d892440Maine State AGfiled 2026-04-10Verified by operator
- bd_0d0fcb4fb3e718f6Texas State AGfiled 2026-04-13(3d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-04-10-legend-senior-living-llc-data-breach-notice-consumers-vt
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 10, 2026
- Raw hash
- e96c1666f9bc8a4a9bd4a9944602009aaf45a3653d145d2c696c7dbf439239ef
Reporting entity
- Name
- Legend Senior Living, LLCnorm: legend senior living
- Domain
- legendseniorliving.com
Victim entity
- Name
- Legend Senior Living, LLCnorm: legend senior living
- Domain
- legendseniorliving.com
Incident
- Discovered
- Jul 27, 2025
- Materiality determined
- Apr 10, 2026
- Notification sent
- Apr 10, 2026
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified relevant regulatory agenciesProvided written notice to relevant state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 37 weeks(257 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.