← Blog

Brome Bird Care Breach: Vermont AG Lists 13 SSNs

Share on X

Vermont’s Attorney General listed Brome Bird Care Inc. on a 4 September 2026 security-breach notice: 13 Vermont residents, with Social Security Numbers among the personal information reported. Brome is a Canadian bird-feeder and garden-products company (bromebirdcare.com). The Vermont AG table is the primary public attestation — a small-state floor on a possibly larger national incident whose full census remains unpublished.

If you are a Vermont customer whose SSN sat in Brome’s systems, treat this as a confirmed Brome Bird Care data breach for regulatory purposes in that state. Canonical record: brome-bird-care-vt2026.

What the Vermont AG filing says

The Vermont Attorney General security breach notices table includes a row dated 9-4-2026 for Brome Bird Care Inc., categorized as Other Commercial, reporting 13 Vermont residents affected, with data type listed as Social Security Numbers.

That is the lead fact set. Secondary aggregators have described broader field lists (full name, email, and additional types). Those secondary summaries are useful as leads for further research; they are not a substitute for the AG table. This article leads with Vermont’s attested count and SSN marker, then explains why a 13-person Vermont notice can still matter to customers elsewhere.

What this is not: a company blog post with a global headcount, a ransomware leak-site dump with screenshots, or a claim that only thirteen humans on Earth were in the underlying system. State AG tables report residents of that state. National impact can be larger and still unpublished.

Who Brome Bird Care is

Brome Bird Care sells bird feeders, seed accessories, and related outdoor products to a North American consumer audience. The brand is recognizable to backyard birders; it is not a hospital, bank, or telecom. That niche status is exactly why SSN exposure surprises people. Specialty retailers still collect government identifiers for warranty registrations, financing partners, employment, tax forms, or fraud checks — and those identifiers travel into the same CRM and ERP stacks that hold shipping addresses.

A breach notice that names Social Security Numbers means someone at Brome (or a processor Brome uses) had reason to store them. The Vermont filing does not publish the business purpose. Customers should assume the worst practical case for identity fraud without inventing a specific database schema.

Records affected: how to read “13”

BreachHistory indexes recordsAffected: 13 as the Vermont AG–reported count of Vermont residents, not as a verified worldwide total. If Brome later publishes a national census, the catalog should update. Until then:

  • 13 = Vermont residents reported to the Vermont AG on the 9-4-2026 notice row.
  • National total = unknown / unpublished in the primary AG source.
  • Secondary sites that list extra data types do not automatically enlarge the Vermont headcount.

Readers searching “how many people in the Brome Bird Care data breach” should see that distinction in the first screen. Inflating 13 into “thousands” without a filing is fiction. Shrinking the story to “only Vermont bird feeders matter” is also wrong — SSNs are portable harm, and phishing will not respect state lines.

What data was exposed

Primary (Vermont AG table): Social Security Numbers, for 13 Vermont residents.

Secondary aggregator claims (treat as unverified relative to the AG row unless a consumer letter surfaces): full name, email address, and additional unspecified fields. If you receive a Brome consumer notice letter, trust the letter’s field list over a lawsuit-lead directory.

SSNs alone are enough to prioritize freezes and tax-fraud monitoring. Names and emails — if truly in scope — mainly improve phishing conversion. Do not wait for a perfect field inventory to freeze credit if you are a Vermont resident who got a notice, or a non-Vermont customer who has reason to believe Brome held your SSN.

Timeline and unknowns

Public primary fact: AG notice dated 4 September 2026. The Vermont table row does not, in the summary columns, publish the underlying incident date, discovery date, attack method, or whether a third-party vendor was involved. Vermont law requires businesses to notify the AG and consumers on defined clocks after discovery; the public table is the visible tip of that process.

Open questions:

  • When the unauthorized acquisition occurred and when Brome discovered it
  • Whether the root cause was ransomware, stolen credentials, a processor breach, or misconfiguration
  • How many non-Vermont individuals are in the same dataset
  • Whether Canadian privacy regulators will publish a parallel notice
  • Whether consumer letters offer credit monitoring enrollment

Absence of those details in the AG table is normal for summary listings. It is not permission to invent a novel attack story. Stick to SSNs + 13 Vermont residents until primary documents expand.

Who is at risk

The 13 Vermont residents in the AG filing. If you received a Brome or Vermont-related notice around early September 2026 mentioning SSN exposure, you are the core attested audience.

Other U.S. and Canadian customers whose SSNs or SINs may sit in the same system. National impact may be larger; it is unpublished. If Brome ever collected your SSN for any reason, ask the company directly whether you are in scope rather than assuming Vermont’s 13 is the whole world.

Employees or contractors if HR files were involved — not stated in the AG data-type column, which lists SSNs without saying customer vs workforce. Do not invent; do read any employee notice carefully.

People with no Brome relationship who still receive “Brome Bird Care breach — verify SSN” phishing. Brand-jacking ignores purchase history.

Why a small Vermont count still deserves a full write-up

Thirteen people is a rounding error in mega-breach headlines. It is not a rounding error if one of those thirteen is your parent and their SSN is in criminal hands. State AG portals exist so small-population harms are visible. Specialty retail breaches also teach a sector lesson: garden and outdoor brands are soft targets with real identity data and thinner security press coverage than banks.

From a catalog perspective, verified regulator filings qualify even when the headcount is modest. Skipping them trains readers to ignore anything under six figures. Identity thieves do not skip them.

What Vermont’s breach law implies (without overclaiming)

Vermont’s Security Breach Notice Act requires notice to consumers and to the Attorney General when personal information is reasonably believed to have been acquired without authorization. The public notices table is how researchers spot filings like Brome’s. Preliminary AG notices can be confidential; the published table row is what the public can cite.

For consumers, the practical takeaway is simpler than the statute: a Vermont AG listing that names SSNs means you should treat identity monitoring as mandatory if you are in that thirteen, and you should be skeptical of anyone who contacts you first claiming to “help with the Brome notice.”

Was I affected by the Brome Bird Care breach?

  • Vermont resident who received a consumer notice → yes for state reporting purposes; follow the letter.
  • Vermont resident who bought from Brome but got no letter → not automatically in the 13; contact Brome through official channels if you previously provided an SSN.
  • Non-Vermont customer → outside the AG’s numbered set; national scope unknown. If you provided an SSN to Brome, ask the company.
  • Never a customer, never an employee → outside the dataset; still ignore Brome-themed SSN phishing.

Do not paste your SSN into a random “Brome breach checker.” Do not send a W-2 photo to a Facebook “support admin.”

What you should do

  1. If you received a letter, keep it. Note the data types and any monitoring offer enrollment deadline.
  2. Place a credit freeze with Equifax, Experian, and TransUnion if your SSN may be involved. Freezes are free and stop most new-account fraud cold.
  3. Consider an IRS IP PIN if you are a U.S. taxpayer whose SSN was exposed.
  4. Monitor tax transcripts and credit reports for new accounts or employer filings you do not recognize.
  5. Contact Brome only through bromebirdcare.com typed by you — not through links in SMS — if you need to ask whether you are in scope.
  6. Vermont residents can use Vermont AG consumer resources for identity-theft guidance; do not confuse that with giving your SSN to a cold caller claiming to be the AG’s office.
  7. Tell household members that “Brome Bird Care compliance” will not call asking them to read Social Security numbers aloud.
  8. If money or tax refunds move strangely, document everything and report to the FTC identitytheft.gov playbook and local law enforcement as appropriate.

Phishing you should expect

  • “Brome Bird Care: Vermont AG requires you to re-enter your SSN at this portal.”
  • “Your bird-feeder warranty is suspended until you verify identity after the breach.”
  • “IRS noticed the Brome leak — confirm your refund routing.”
  • “Canadian privacy office fine — pay CAD 1.99 to close your file.”
  • Lookalike domains swapping characters in “brome” or “birdcare.”

The real Vermont AG site is ago.vermont.gov. The real company site is bromebirdcare.com. Anything that demands your SSN in a hurry after a breach headline is hostile until proven otherwise.

Industry context: specialty retail and quiet SSN stores

Outdoor, pet, and hobby retailers rarely make the front page of cybersecurity Twitter. They still run the same Shopify-adjacent stacks, the same ERP plugins, the same “upload passport for warranty” workflows that larger brands run. When SSNs appear in an AG table for a bird-feeder company, the lesson is not that birding is uniquely dangerous. The lesson is that identity data follows commerce into unexpected verticals.

Compare without inventing a shared actor: other 2026 commercial AG notices also surface small state counts with high-sensitivity fields. Researchers who only chase million-record dumps miss the long tail where synthetic identity fuel is gathered. Brome’s Vermont row belongs in that long tail — verified, labeled with a state floor, open about national unknowns.

Company and regulator silence gaps

As of the public AG table row, there is no detailed consumer FAQ in the primary source describing malware, dwell time, or whether a vendor was involved. Secondary lawsuit-lead pages sometimes expand field lists to drive intake forms. Prefer primary documents. If Brome publishes a notice on its site, that becomes the next authoritative layer. If Canadian authorities publish, that becomes another. Until then, the Vermont AG table is the spine.

BreachHistory will update brome-bird-care-vt2026 if a national census or richer field inventory appears in a primary notice. Do not treat scraped “+6 more data types” blurbs as company confirmation.

Canonical record and sources

Canonical BreachHistory page: 2026 Brome Bird Care — Vermont AG notice, 13 residents, SSNs.

Primary source: Vermont Attorney General — Security Breach Notices (row dated 9-4-2026, Brome Bird Care Inc., 13, Social Security Numbers).

For Vermont residents specifically

You live in a state that publishes breach notice summaries in a usable table. That transparency helps — and it creates a phishing surface, because scammers also read the table. If a caller already knows you might be one of thirteen, they may claim “we’re calling only the Vermont group.” That is not proof they are Brome or the AG. Ask which written notice they sent, then verify through channels you initiate.

If you did not provide an SSN to Brome and still got a letter, take the letter seriously anyway — someone thought your SSN was in the file. Freeze credit first; argue data provenance second.

For customers outside Vermont

You are not in the AG’s numbered thirteen. You may still be in an unpublished larger set. Reasonable steps: search your email for Brome order confirmations; remember whether you ever typed an SSN into a warranty, financing, or employment flow tied to the brand; contact official support if yes. Reasonable non-steps: panic-buying credit products from banner ads on breach news aggregators; sending SIN/SSN photos to strangers.

Canadian customers should remember that Vermont’s table is a U.S. state filing. Parallel Canadian notifications, if required, follow different clocks and may not mirror the Vermont headcount.

FAQ

How many people were affected? Vermont reported 13 residents. National total is unpublished in that primary source.

What data types are confirmed? Social Security Numbers, per the Vermont AG table. Broader lists from secondary aggregators are not treated here as primary confirmation.

Is this verified? Yes — as a regulator-filed security breach notice in Vermont dated 4 September 2026.

Did Brome confirm on its website? This write-up is anchored on the AG table. Check bromebirdcare.com for any later company FAQ; prefer typed URLs.

Should I freeze my credit over a bird-feeder brand? If your SSN may be involved, yes. The product category does not reduce SSN harm.

Why catalog a 13-person incident? Verified regulator attestation, high-sensitivity data type, and clear phishing risk. Size is not the only significance test.

Action checklist if you already froze credit last year

Freezes stay until you lift them. Confirm each bureau still shows a freeze. Add fraud alerts if you prefer temporary alerts over freezes. Review whether any new bureau or specialty consumer-reporting agency (chexsystems-style) matters for your banking. SSN exposure is multi-year, not a one-week news cycle.

If you enroll in any monitoring Brome may offer later, use the enrollment code from a mailed letter or a domain you typed — not from a Google ad titled “Brome Bird Care data breach claim now.”

How researchers should cite this incident

Cite the Vermont AG security breach notices table with the 9-4-2026 date, entity name Brome Bird Care Inc., resident count 13, and data type Social Security Numbers. If you also cite a secondary aggregator that lists full name and email, label that layer clearly as secondary. Mixing layers without labels is how “13 Vermonters with SSNs” quietly becomes “millions of birders with everything” in Slack threads.

For BreachHistory’s catalog row, the canonical path is /brome-bird-care/brome-bird-care-vt2026, with recordsAffected set to the Vermont AG floor of 13 and prose that states the national unknown.

If you shared an SSN for a warranty or financing flow

Specialty retailers sometimes collect SSNs through financing partners, fraud-check vendors, or employment onboarding rather than through the storefront cart. You may not remember which form asked. Search email for “Brome,” warranty PDFs, and any Affirm-/Synchrony-style financing confirmations tied to a feeder purchase. If a financing partner held the SSN, that partner’s own notice rules may apply separately — still freeze credit while you sort which vendor is primary.

Employees who worked seasonal warehouse or customer-service shifts should check whether an HR notice arrived on a different timeline than the Vermont consumer table. Workforce SSNs and customer SSNs can share an incident without sharing a public row format.

Cross-border practicalities for Canadian households

Brome is a Canadian company selling into the United States. A Vermont filing does not automatically describe PIPEDA or provincial notice status. Canadian households that provided a Social Insurance Number (different from a U.S. SSN) should not assume the Vermont SSN column speaks to them — and should not ignore the brand’s name in phishing either. If you only ever gave a shipping address and email, your risk profile differs from someone who typed a government ID number into a form. Ask the company which identifiers were in scope before you assume the worst or the best.

What remains open

Root cause, national census, full field inventory, and consumer-letter benefits are open. The closed, citable facts are enough to act: Vermont AG notice dated 4 September 2026; Brome Bird Care Inc.; 13 Vermont residents; Social Security Numbers. That is a verified Brome Bird Care data breach filing. Treat SSNs as exposed for those residents; treat national scope as unknown; treat urgent SSN-collection messages as hostile.

Specialty retail will keep appearing in state AG tables. The brands will sound niche. The data types will not. When the next birding, gardening, or hobby retailer shows up next to an SSN column, you will already know the playbook — because Brome’s September 2026 Vermont notice wrote it in thirteen lines of public record.