HackingRansomwareData ExfiltratedRansom DemandedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENTMediumContained
Growers Express
bd_18f1e3e19cfa00f1 · schema v1 · pii pii-v1
Full breach record for Growers Express →Growers Express, LLC disclosed a sophisticated computer attack where an external actor accessed employee data files with the goal of extortion. On October 9, 2023, the company discovered that personal information, including names, addresses, SSNs, and direct deposit info, was exfiltrated. The breach occurred on September 20, 2023. The company isolated the attack, reported it to law enforcement, and is offering two years of identity monitoring via Kroll to affected former employees.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_ec14dcca25364222Leak Sitebianlianfiled 2023-11-21(16d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_7556f6d2f1b3f250Montana State AGfiled 2023-11-05Verified by operator
- bd_bf506943a32b58caMaine State AGfiled 2023-11-05Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576114
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 5, 2023
- Raw hash
- a88ee59ec6130b297dbd518c7d6e08af378fdcfcf2846b4ba90073e16d62ee44
Reporting entity
- Name
- Growers Expressnorm: growers express
Victim entity
- Name
- Growers Expressnorm: growers express
Incident
- Discovered
- Oct 9, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the attack to law enforcement
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.