Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CorVel
bd_fe77d469cc7ea8bf · schema v1 · pii pii-v1
Full breach record for CorVel →CorVel notified consumers of a data breach caused by a phishing email that compromised an employee's credentials. The incident exposed personal information including names, addresses, and government IDs. CorVel is offering 24 months of identity theft protection and credit monitoring services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-27-corvel-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2026
- Raw hash
- 209e33e3fcdcb47cd4c21885b9aafaf037d4eeb0b80ce1ea0ba135494e63fba1
Reporting entity
- Name
- CorVelnorm: corvel
Victim entity
- Name
- CorVelnorm: corvel
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.