PUMA North America, Inc.
bd_19ebc5a096f4e012 · schema v1 · pii pii-v1
Full breach record for PUMA North America, Inc. →PUMA North America, Inc. notified the California AG of a ransomware attack on its vendor, UKG Inc. (Kronos). The attacker accessed UKG's cloud environment earlier in 2021, stole data, and encrypted systems. Service interruptions were discovered on December 11, 2021. Personal information of PUMA employees and their dependents (including minors) was compromised. UKG offered 24 months of identity monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2021
Begins
Dec 11, 2021
Discovered
Feb 3, 2022
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Maine State AGbd_2f6215e58a3bea962022-02-03Candidate
- Indiana State AGbd_52546b114e3f188c2022-02-03Verified
- Massachusetts State AGbd_fd12498c0e523b892022-02-03Verified
- New Hampshire State AGbd_52794aa7156493342022-02-08 · +5dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Feb 3 (ME), last Feb 8 (NH) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.