MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
HEAVY CONSTRUCTION SYSTEMS SPECIALISTS, INC.
bd_1003dcc4662eaf22 · schema v1 · pii pii-v1
Full breach record for HEAVY CONSTRUCTION SYSTEMS SPECIALISTS, INC. →Heavy Construction System Specialists, LLC (HCSS) notified the Maryland Attorney General of a ransomware attack detected on October 18, 2024. The incident affected 2 Maryland residents (employees/former employees), exposing names, addresses, phone numbers, employee IDs, and Social Security Numbers. HCSS engaged cybersecurity experts and law enforcement, and offered 24 months of credit monitoring via Experian IdentityWorks.
Leak gap clock✗ Leak >180d13 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 397 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_3b2b6a3616578f4aLeak Sitemedusafiled 2024-10-11(397d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_1c9ce00e4c47f463Texas State AGfiled 2026-01-05(53d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376135.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- e890ca35ec5477f9e0f3dfcb34883bdf679e777e1ac14dc81be142ac87047b12
Reporting entity
- Name
- Kirkland & Ellis LLPnorm: kirkland ellis
- Domain
- kirkland.com
Victim entity
- Name
- HEAVY CONSTRUCTION SYSTEMS SPECIALISTS, INC.norm: heavy construction systems specialists
- Domain
- hcss.com
Incident
- Discovered
- Oct 18, 2024
- Materiality determined
- —
- Notification sent
- Dec 18, 2024
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General
Compliance
- Time to disclose
- 13 months(391 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.