MalwareRansomwareRansom DemandedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
American Frame Corporation
bd_2664ce40a4d83da6 · schema v1 · pii pii-v1
Full breach record for American Frame Corporation →American Frame Corporation, a custom frame and art printing service, detected a ransomware attack on August 1, 2020. An unauthorized third party attempted to infiltrate the network, encrypt data, and demand ransom. Employee PII (name, address, SSN) and customer credit card information were potentially exposed. The company engaged forensic specialists, secured the network, and offered credit monitoring.
California clockDiscovered Aug 1, 2020 → Notified Jan 14, 2021166d ✗ CA 60-day late25 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_6742a8cb5abf4d18Maine State AGfiled 2021-01-25Candidate
- bd_73e0008263304121Washington State AGfiled 2021-01-25Verified
- bd_dd80bc80763b9b51Oregon State AGfiled 2021-01-25Verified
- bd_ef07f78a5213490dMontana State AGfiled 2021-01-14(11d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-537411
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 25, 2021
- Raw hash
- c9543b2f6ece5a641063d91bf19444cc7b118ead2bead79ad679e5adbf9ec52d
Reporting entity
- Name
- American Frame Corporationnorm: american frame
Victim entity
- Name
- American Frame Corporationnorm: american frame
Incident
- Discovered
- Aug 1, 2020
- Materiality determined
- —
- Notification sent
- Jan 14, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 25 weeks(177 days from discovery to filing)
- Compliance flags
- CA 60-day late · 166d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 1, 2020→ Notified: Jan 14, 2021166d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.