HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Ahtna Incorporated
bd_12ccee8c9159108c · schema v1 · pii pii-v1
Full breach record for Ahtna Incorporated →Ahtna, Inc. reported unauthorized access to its systems by a third party between April 20, 2025, and June 1, 2025. The company became aware of the incident on July 28, 2025. The investigation confirmed that certain files containing personal information, including names and Social Security numbers, were acquired by the unauthorized party. Ahtna contained the network, engaged outside professionals for investigation, and is offering 12 months of credit monitoring and identity restoration services to affected individuals.
California clockDiscovered Jul 28, 2025 → Notified Nov 21, 2025116d ✗ CA 60-day late17 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2ff3c11d1751fbb2Maine State AGfiled 2025-11-21Candidate
- bd_31c06274ced5bd37Indiana State AGfiled 2025-11-21Verified
- bd_90c6835deaec4751Vermont State AGfiled 2025-11-21Verified
- bd_f23a1a2a204c96b5New Hampshire State AGfiled 2025-11-21Verified
Show 2 more filings ↓Show fewer ↑up to 91d gap
- bd_11bf1ab7ad30a689California State AGfiled 2026-01-20(60d gap)Verified
- bd_4e509ebc850ec1d9Texas State AGfiled 2026-02-20(91d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-614613
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2025
- Raw hash
- fe8a524a2dbd18ae1371bc5b7ff3a2273e1654bd9eb0b56ae2dc2187b3004f82
Reporting entity
- Name
- Ahtna Incorporatednorm: ahtna
- Domain
- ahtna.com
Victim entity
- Name
- Ahtna Incorporatednorm: ahtna
- Domain
- ahtna.com
Incident
- Discovered
- Jul 28, 2025
- Materiality determined
- —
- Notification sent
- Nov 21, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- CA 60-day late · 116dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 28, 2025→ Notified: Nov 21, 2025116d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.