HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMINORCriticalActive
ZOLL Medical
bd_0508d77c64b573f8 · schema v1 · pii pii-v1
Full breach record for ZOLL Medical →Zoll Medical Corporation notified Delaware AG of a cybersecurity incident detected on January 28, 2023, affecting patient, employee, and minor dependent data. The breach involved unauthorized access to internal networks, resulting in the disclosure of names, SSNs, DOBs, and health information. ZOLL engaged third-party experts, notified law enforcement, and offered credit monitoring. The investigation was ongoing as of the March 10, 2023 notification date.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_142152a27cb186ddCalifornia State AGfiled 2023-03-10Verified
- bd_15a1da436523208cDelaware State AGfiled 2023-03-10Verified
- bd_3dc114db9cf57c6fVermont State AGfiled 2023-03-10Verified
- bd_45b338a33a1fe783Washington State AGfiled 2023-03-10Verified
Show 3 more filings ↓Show fewer ↑up to 3d gap
- bd_bfd7269fa3840225Maine State AGfiled 2023-03-10Verified
- bd_e0ffd0dc853fa19dOregon State AGfiled 2023-03-10Verified
- bd_2bbe6c0aee4246d1New Hampshire State AGfiled 2023-03-13(3d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/03/Delaware-Notification-Letters.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 10, 2023
- Raw hash
- 0ca10a09f2b2846c2e85628a34282830217e674ddc432a112ef4711326a16c64
Reporting entity
- Name
- ZOLL Medicalnorm: zoll medical
- Domain
- zoll.com
Victim entity
- Name
- ZOLL Medicalnorm: zoll medical
- Domain
- zoll.com
Incident
- Discovered
- Jan 28, 2023
- Materiality determined
- —
- Notification sent
- Mar 10, 2023
- Affected individuals
- 105,306
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified federal and state regulatory agencies as required by law
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.