HackingStolen CredentialsTargetedIDENTITY_BASICPIILowContained
ACE HARDWARE CORPORATION
bd_14fe6f10df22344f · schema v1 · pii pii-v1
Full breach record for ACE HARDWARE CORPORATION →Ace Hardware Corporation notified Vermont consumers of a data breach occurring October 27-29, 2023. Unauthorized actors accessed corporate network data including names and other personal identifiers. No evidence of misuse was found. Ace engaged forensic specialists and law enforcement, implemented technical safeguards, and offered 12 months of credit monitoring.
Vermont clock✗ VT AG >45 bday22 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_7c78088a02e5030cMontana State AGfiled 2024-04-01Candidate
- bd_81142c7264dd1e84Indiana State AGfiled 2024-04-01Verified
- bd_87a490160af062c6California State AGfiled 2024-04-01Verified
- bd_9b3e5f42ce97e604Maine State AGfiled 2024-04-01Verified by operator
Show 2 more filings ↓Show fewer ↑
- bd_be41d37097e367dfWashington State AGfiled 2024-04-01Verified
- bd_cf8415c312a4875bNew Hampshire State AGfiled 2024-04-01Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-01-ace-hardware-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 1, 2024
- Raw hash
- b45369f5b2986e99bb557e3ac008d2579f91c85a53764f5161778a7e73997513
Reporting entity
- Name
- ACE HARDWARE CORPORATIONnorm: ace hardware
Victim entity
- Name
- ACE HARDWARE CORPORATIONnorm: ace hardware
Incident
- Discovered
- Oct 29, 2023
- Materiality determined
- Apr 1, 2024
- Notification sent
- Apr 1, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Worked closely with law enforcement who is conducting an active investigation into the unauthorized actor responsible for this incident
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(155 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.