HackingEmployee Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
iBUYPOWER
bd_33089f431df75368 · schema v1 · pii pii-v1
Full breach record for iBUYPOWER →American Future Technology Corporation d/b/a iBUYPOWER experienced a data security incident involving unauthorized access to employee personal information. The breach was discovered on June 21, 2025, with unauthorized activity occurring between June 18 and June 21, 2025. Affected data includes SSNs, driver's license numbers, bank account numbers, and medical information. The company engaged cybersecurity specialists, contained the incident, and offered identity restoration services.
California clockDiscovered Jun 21, 2025 → Notified Jun 5, 2026349d ✗ CA 60-day late51 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_6c448c2b3e8d13e3Leak Sitelynxfiled 2025-06-20(357d gap)Verified by operator
Regulatory filings (1) · sorted by filing gap
- bd_c47613a84681af76New Hampshire State AGfiled 2026-06-05(7d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-624771
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 12, 2026
- Raw hash
- b49e0d1f587ded3b6f0bb72c0682523dabdc0c076f67b216a3e8f88881f45aba
Reporting entity
- Name
- iBUYPOWERnorm: ibuypower
- Domain
- ibuypower.com
Victim entity
- Name
- iBUYPOWERnorm: ibuypower
- Domain
- ibuypower.com
Incident
- Discovered
- Jun 21, 2025
- Materiality determined
- —
- Notification sent
- Jun 5, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 51 weeks(356 days from discovery to filing)
- Compliance flags
- CA 60-day late · 349dLeak >180dCA AG copy ≤15d · 7d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 21, 2025→ Notified: Jun 5, 2026349d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Jun 5, 2026→ AG copy submitted: Jun 12, 20267d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.