Confirmed breach. Intrusion Mar 31, 2023, discovered Mar 31, 2023 — the first regulatory filing landed 182 days later (flagged late). 164,796 individuals reported across the linked filings.
Financial Asset Management Systems (FAMS) notified consumers of a March 31, 2023 incident where an unauthorized party acquired name and Social Security numbers from its network. FAMS reported the incident to law enforcement, engaged computer specialists, and provided complimentary credit monitoring and identity protection services to affected individuals.
VT AG >45 bdayLeak >90d
32 days
🍁Vermont State AGlinked via same-victim cross-source · 100%
Financial Asset Management Systems (FAMS) notified consumers of a March 31, 2023 incident where an unauthorized party acquired network data including names and Social Security numbers. FAMS reported the incident to law enforcement, engaged computer specialists, and provided complimentary credit monitoring and identity protection services to affected individuals.
VT AG >45 bday
🇺🇸GAHHS OCRMost recentlinked via same-victim cross-source · 100%
Financial Asset Management Systems, a Georgia-based business associate, reported to HHS on 2023-11-04 a ransomware incident affecting the PHI of 164,796 individuals. Breached information was located on a network server. PHI involved included names, claims, and financial information. The BA notified HHS, affected individuals, and the media, posted a substitute notice, and provided complimentary credit monitoring. Additional administrative, technical, and security safeguards were implemented.
Affected (this filing): 164,796
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.