MalwareRansomwareCapture Stored DataData EncryptedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATIONLowContained
Avery Products Corporation
bd_17d3515f645117e9 · schema v1 · pii pii-v1
Full breach record for Avery Products Corporation →Avery Products Corporation notified consumers of a ransomware attack discovered on December 9, 2024. Between July 18, 2024, and January 5, 2025, an unauthorized actor scraped credit card information, names, addresses, and CVVs from avery.com. The incident was reported to state regulators and AGs. Affected individuals are offered 12 months of credit monitoring.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_7c5c23e82caf557cNew Hampshire State AGfiled 2025-02-05(7d gap)Verified
- bd_b9944af515ad8d51Maine State AGfiled 2025-02-06(8d gap)Verified
- bd_a2e5641bcdbf5b89Montana State AGfiled 2025-02-07(9d gap)Verified
- bd_a6b982179a1d1f96California State AGfiled 2025-02-11(13d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 19d gap
- bd_0133914d5cd708f9Oregon State AGfiled 2025-01-16(13d gap)Verified
- bd_9622529b26f17acfIndiana State AGfiled 2025-01-16(13d gap)Verified
- bd_9f8cfdfd51be813cCalifornia State AGfiled 2025-01-16(13d gap)Verified
- bd_c0cb72b951b7a3edNew Hampshire State AGfiled 2025-01-13(16d gap)Verified
- bd_dc0171a2cb3b6587Maine State AGfiled 2025-01-13(16d gap)Candidate
- bd_3fc44f2276bcd5a0Washington State AGfiled 2025-01-10(19d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-01-29-avery-products-corporation-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 29, 2025
- Raw hash
- 9ffaa6f526cca7eed3fd9ae9bc52dbd4ebae95e30f815bf2ac8bd106164a4dac
Reporting entity
- Name
- Avery Dennison Corpnorm: avery dennison
- Domain
- averydennison.com
Victim entity
- Name
- Avery Products Corporationnorm: avery products
- Domain
- avery.com
Incident
- Discovered
- Dec 9, 2024
- Materiality determined
- —
- Notification sent
- Jan 29, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1056 Input CaptureT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Incident has been reported to certain state regulators, and Attorneys General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.