MalwareRansomwareData ExfiltratedData EncryptedEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTMediumActive
The North Highland Holding Company LLC
bd_43b6cf6e213c6816 · schema v1 · pii pii-v1
Full breach record for The North Highland Holding Company LLC →The North Highland Company LLC reported a ransomware attack discovered on June 6, 2022, affecting on-premises servers. Attackers gained access around May 26, 2022, and exfiltrated personal information of current and former employees, including names, SSNs, bank account numbers, and health information. The company engaged forensic experts, notified law enforcement, and offered 24 months of Experian IdentityWorks to affected individuals.
California clockDiscovered Jun 6, 2022 → Notified Sep 26, 2022112d ✗ CA 60-day late16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_b03ec36e53e8b9baMaine State AGfiled 2022-09-26Verified
- bd_cd7f068cb537a689Oregon State AGfiled 2022-09-26Verified
- bd_4a5a5be8d6ceb777Montana State AGfiled 2022-09-23(3d gap)Verified
- bd_52c6629a73a1db9dOregon State AGfiled 2022-07-29(59d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 60d gap
- bd_f6fd1512ab6ececbMaine State AGfiled 2022-07-28(60d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-557632
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2022
- Raw hash
- 3c963672d9820f1309b26bb50d75e3b197fd9f014a44849729bbc13ba1489905
Reporting entity
- Name
- The North Highland Holding Company LLCnorm: the north highland
Victim entity
- Name
- The North Highland Holding Company LLCnorm: the north highland
Incident
- Discovered
- Jun 6, 2022
- Materiality determined
- —
- Notification sent
- Sep 26, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- CA 60-day late · 112d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 6, 2022→ Notified: Sep 26, 2022112d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.