HackingStolen CredentialsData ExfiltratedIDENTITY_BASICLowContained
WEL Companies
bd_3282d3512f1a4813 · schema v1 · pii pii-v1
Full breach record for WEL Companies →WEL Companies, Inc. notified South Carolina residents of a data security incident. Unauthorized access to files occurred on March 28, 2025. Personal information, including names and addresses, was potentially affected. WEL engaged cybersecurity experts, reviewed the data, and is offering complimentary identity monitoring through Kroll. No evidence of misuse was found.
Leak gap clock✗ Leak >180d42 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by ransomhub about this victim predates this filing by 293 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_6200adaf03e80244Leak Siteransomhubfiled 2025-02-19(274d gap)Candidate
- bd_2a8934f0f3369533Leak Siteransomhubfiled 2025-01-31(293d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_bfcb985961ca865aCalifornia State AGfiled 2025-11-19(1d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20WEL%20Companies%2C%20Inc..pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2025
- Raw hash
- 67926cc9651d272dbd6d5c6abfb8bcb1e827ece751fad06907118512e4e20bcd
Reporting entity
- Name
- WEL Companiesnorm: wel companies
- Domain
- welcompanies.com
Victim entity
- Name
- WEL Companiesnorm: wel companies
- Domain
- welcompanies.com
Incident
- Discovered
- Jan 31, 2025
- Materiality determined
- —
- Notification sent
- Nov 12, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 42 weeks(293 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.