HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICPHIMediumContained
Self Esteem Brands, LLC
bd_2bbb16e4e6022844 · schema v1 · pii pii-v1
Full breach record for Self Esteem Brands, LLC →Self Esteem Brands, LLC disclosed a cybersecurity incident affecting residents in Maryland, New York, and North Carolina. Unauthorized actors accessed employee email accounts starting December 19, 2023, and viewed/obtained files from servers between June 5-6, 2024. Affected data included names, SSNs, tax IDs, driver's licenses, and potentially financial/health info. The company engaged forensic investigators, notified law enforcement, and provided one year of Equifax credit monitoring. The incident is contained.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376051.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 17, 2025
- Raw hash
- f1b5802b8a6d4d283546a0379b37fe214e3212b84bf4861b36d820b26957b05b
Reporting entity
- Name
- Self Esteem Brands, LLCnorm: self esteem brands
Victim entity
- Name
- Self Esteem Brands, LLCnorm: self esteem brands
Incident
- Discovered
- Jun 6, 2024
- Materiality determined
- —
- Notification sent
- Dec 20, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 19 months(559 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.