MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
AmeriCold
bd_2c4fec73bf2ea11a · schema v1 · pii pii-v1
Full breach record for AmeriCold →Americold Logistics LLC notified Vermont consumers of a cybersecurity incident discovered on April 26, 2023, involving malware deployment and data exfiltration. Affected data included names, SSNs, driver's licenses, financial account numbers, and health insurance information. The company engaged forensic investigators, reported to law enforcement, and offered two years of complimentary identity monitoring.
Vermont clock✗ VT AG >45 bday32 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0cac8bbf3d5a932cCalifornia State AGfiled 2023-12-08Verified
- bd_9e9da069ab209cc8Maine State AGfiled 2023-12-08Candidate
- bd_bb46f50d69e5ca3fOregon State AGfiled 2023-12-08Verified
- bd_f1c81e9d6f9d9efeWashington State AGfiled 2023-12-08Verified by operator
Show 1 more filing ↓Show fewer ↑
- bd_f7cc524490b4564fMontana State AGfiled 2023-12-08Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-08-americold-logistics-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2023
- Raw hash
- 761536a4a73266c2afe115b64bf0a6439df17210f962c07afcca3fec35b6753b
Reporting entity
- Name
- AmeriColdnorm: americold
- Domain
- americoldinc.com
Victim entity
- Name
- AmeriColdnorm: americold
- Domain
- americoldinc.com
Incident
- Discovered
- Apr 26, 2023
- Materiality determined
- Dec 8, 2023
- Notification sent
- Dec 8, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the matter to law enforcement
Compliance
- Time to disclose
- 32 weeks(226 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.