HackingData ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumResolved
PACCAR INC
bd_396e87c59bc40b92 · schema v1 · pii pii-v1
Full breach record for PACCAR INC →Navistar, Inc. disclosed a security incident where an unauthorized third party accessed and extracted data from its IT system prior to May 20, 2021. The breach affected current and former employees and their dependents, exposing names, addresses, dates of birth, Social Security numbers, and health plan participation details including provider and prescription information. Navistar engaged cybersecurity experts, enhanced security protocols, and offered two years of credit monitoring.
California clockDiscovered May 20, 2021 → Notified Sep 21, 2021124d ✗ CA 60-day late18 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fc56b39267778160Maine State AGfiled 2021-09-20(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-545568
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 21, 2021
- Raw hash
- d0586abd93c0ea7f50add0cad524964264ebd739549f10ec7134de78fab564a1
Reporting entity
- Name
- PACCAR INCnorm: paccar
- Domain
- navistar.com
Victim entity
- Name
- PACCAR INCnorm: paccar
- Domain
- navistar.com
Incident
- Discovered
- May 20, 2021
- Materiality determined
- —
- Notification sent
- Sep 21, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 18 weeks(124 days from discovery to filing)
- Compliance flags
- CA 60-day late · 124d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 20, 2021→ Notified: Sep 21, 2021124d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.