DisclosureLens
MalwareManufacturingManufacturingRansomwareCapture Stored DataData ExfiltratedData EncryptedEmployee Data InvolvedTargetedIdentity (basic)Government IDHealth (basic)MediumContained

SI Group, Inc.

bd_2ba8825ab3d00a6d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 14, 2021

Filed

Oct 26, 2021

To disclose

10 weeks

Affected

4state residents only

Linked

10 filings

Confidence

63%
Full breach record for SI Group, Inc.

SI Group, Inc. notified Montana residents of a ransomware attack occurring between August 9-14, 2021. The incident resulted in the unauthorized access and exfiltration of employee personal information, including SSNs, driver's licenses, and health data. SI Group engaged forensic experts, isolated networks, and notified law enforcement. Affected individuals were offered two years of credit monitoring via Equifax.

Incident timeline

undetected · 5 days
discovery → filing · 10 weeks / 73 days

Aug 9, 2021

Begins

Aug 14, 2021

Discovered

Oct 26, 2021

Filed

This filing is one of 10 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (9) · sorted by filing gap

Show 5 more filingsup to 77d gap

Filing propagation · 10 filings · 6 states

View merged incident ↗

Pattern: first filing Sep 29 (IN), last Jan 11 (NH) — a 104-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.