MalwareRansomwareData EncryptedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Dayton Superior
bd_01e854a6eac5f768 · schema v1 · pii pii-v1
Full breach record for Dayton Superior →Dayton Superior Corporation, a manufacturing firm, notified the New Hampshire Attorney General of a ransomware incident affecting 2 NH residents. On July 24, 2022, internal tools detected databases and files being encrypted. The company isolated systems, engaged forensic experts, and notified the FBI and DHS. Compromised data included employee PII (SSNs, driver's licenses, health data). Notifications to affected individuals began August 19, 2022, offering 2 years of credit monitoring.
Leak gap clock⏱ Leak >30d5 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
A leak claim by lockbit_3 about this victim predates this filing by 36 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/dayton-superior-20220829.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2022
- Raw hash
- 5faf3400196f7772bb23d85f09ad1129225a03fee8604fa2bcf898ec1fa3c276
Reporting entity
- Name
- Dayton Superiornorm: dayton superior
- Domain
- daytonsuperior.com
Victim entity
- Name
- Dayton Superiornorm: dayton superior
- Domain
- daytonsuperior.com
Incident
- Discovered
- Jul 24, 2022
- Materiality determined
- —
- Notification sent
- Aug 19, 2022
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Attorney General of New HampshireProactively engaged both the Federal Bureau of Investigation and the U.S. Department of Homeland Security
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.