
The Chaos ransomware group listed Miles Partnership, a Sarasota tourism-marketing firm serving more than 130 destinations and hospitality clients, on its leak site on February 26, 2026, threatening a full data dump absent negotiation — a claim logged independently by three separate leak-site trackers on the same date, the same pattern of attacker-publishes-first seen elsewhere this year. Miles Partnership's own notification to Massachusetts and Vermont regulators, and to affected individuals, didn't go out until July 31, 2026: Social Security numbers, financial account information, and driver's license data. The company's site carries no public breach notice; what's known comes from the regulatory filing and the class-action firms that picked it up afterward, none of which state a cause.
Why the gap is bigger than it looks
Vermont's breach law gives a business 45 days from discovery to notify affected residents, with a preliminary notice to the state due within 14 business days. Massachusetts uses a looser standard — "as soon as practicable and without unreasonable delay" — read by regulators as days to weeks, not months. If Miles Partnership's own discovery date lines up anywhere near when Chaos went public, July 31 lands 110 days past Vermont's statutory deadline. That's a real possibility, not a confirmed fact: the company hasn't disclosed when it discovered the incident, and discovery and a public extortion-site listing aren't always the same event.
That uncertainty is the actual story. "Discovery" is a defined legal trigger — when you knew or reasonably should have known unauthorized access occurred — not the moment a forensic firm finishes scoping the damage. Most incident-response plans treat those as the same moment, because waiting for scope feels more responsible than notifying with an incomplete picture. In practice, the clock doesn't start until someone with authority decides it should — and a criminal group posting your name on a leak site is exactly the kind of event a plaintiff's attorney will later argue should have started it.

The practice: define "discovery" before an incident forces the definition on you
The useful version of this isn't "notify faster." It's a decision rule written down before anyone needs it:
- Name the trigger events that count as discovery, per jurisdiction, in advance. Most state statutes, Vermont's included, set the bar at reasonable belief that unauthorized access occurred — not confirmed scope. A ransomware group publicly claiming your organization, an employee reporting anomalous behavior, or a third party flagging your own exposed data all qualify. An IR plan that waits for forensic confirmation is using a stricter standard than the law does.
- Build the jurisdiction matrix before you're in an incident. Every state with your residents in it has its own deadline and its own definition of discovery — Vermont's 45 days is specific and unusually short; most states name no number at all. Assembling this three weeks into a live incident is how the short deadlines get missed.
- Monitor leak-site trackers for your own organization's name. Ransomware.live and similar aggregators are public and free, and a listing there is itself a discovery-triggering event under most statutes, confirmed or not. Treat an alert as a same-day call to counsel, not a wait-and-see.
- Notify with what you have, then supplement. Most state laws, Massachusetts's included, permit an initial notice on available information followed by a supplemental one once scope is confirmed. Waiting for certainty before sending anything is the most common, and most avoidable, reason the clock runs long.
None of this is free. Locking a discovery date early starts an obligation before the full scope is known, which can mean a second, corrected notice later — a worse look in the short term than staying quiet, even though it's the legally sounder position. Leak-site monitoring throws false positives from copycat and reused listings that need triage. Both cost less than discovering your discovery date in a deposition.
If you're not ready to name a date this week, the narrower fallback still holds: escalate any leak-site mention or credible extortion contact to counsel within 24 hours, and let counsel make the discovery-date call in writing — rather than letting it default to "whenever forensics finishes."
What to check this week
- Does your incident-response plan define "discovery" as reasonable belief or forensic confirmation — and can you point to the sentence that says so?
- Do you have a current, jurisdiction-by-jurisdiction notification deadline matrix for every state where you hold even one resident's data?
- Is anyone — internal staff or your IR retainer — checking leak-site trackers for your organization's name on a recurring basis?
- If you hold data for clients, the way Miles Partnership holds guest and prospect data for its destination clients, does your contract with them require you to notify them on a deadline shorter than your own regulatory one?
None of this establishes what actually happened inside Miles Partnership between February and July — that isn't disclosed, and this piece doesn't guess at it. What's confirmed is the shape of the gap and the deadline it likely ran past, a shape any organization can end up in without a plan that defines "discovery" before an incident forces the definition on it. A related version of this same ambiguity, under a federal clock instead of a state one, is in where the 60-day HIPAA breach clock actually starts.
North InfoSec's security consulting includes incident-response and breach-notification planning, including the jurisdiction-by-jurisdiction obligation matrix described above. northinfosec.com