MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
HANESBRANDS INC.
bd_1bff8c804887df1d · schema v1 · pii pii-v1
Full breach record for HANESBRANDS INC. →Hanesbrands, Inc. disclosed a ransomware incident detected on May 24, 2022, impacting internal IT systems. The incident was contained. Personal information affected included contact info, DOB, financial account data, government IDs (SSN, driver's license), and limited health information. The company reported to law enforcement, strengthened network security, and offered two years of Experian IdentityWorks protection.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_77190cfcd636f76fCalifornia State AGfiled 2022-11-29Verified
- bd_c9aa4e72eaff47ccOregon State AGfiled 2022-11-29Verified
- bd_6bad099dc259b08fMaine State AGfiled 2022-11-30(1d gap)Verified
- bd_416bfab051b743caWashington State AGfiled 2022-11-23(6d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 105d gap
- bd_8c1ac18743a5161dOregon State AGfiled 2022-09-30(60d gap)Verified
- bd_9fb9627acb7eb000Montana State AGfiled 2022-08-16(105d gap)Candidate
- bd_f71ffedbeab73a05California State AGfiled 2022-08-16(105d gap)Verified
- bd_f9d4220f22ced5eeMaine State AGfiled 2022-08-16(105d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hanesbrands-20221129.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 29, 2022
- Raw hash
- 58d289821d6e183b64e7c31ccdf1b8971eab84977256822543c1d60cb1af35be
Reporting entity
- Name
- HANESBRANDS INC.norm: hanesbrands
Victim entity
- Name
- HANESBRANDS INC.norm: hanesbrands
Incident
- Discovered
- May 24, 2022
- Materiality determined
- —
- Notification sent
- Nov 29, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to law enforcement
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.