MalwareManufacturingRetail & ConsumerManufacturingRansomwareRansom DemandedData EncryptedCustomer Data InvolvedEmployee Data InvolvedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Consolidated Brick & Building Supplies, Inc.
bd_479781ca8b76e625 · schema v1 · pii pii-v1
Full breach record for Consolidated Brick & Building Supplies, Inc. →Consolidated Brick & Building Supplies, Inc. (Avon, MA) suffered a ransomware attack discovered on July 10, 2024, affecting its internal systems. Investigation completed August 3, 2024 confirmed unauthorized actor access to systems containing employee name, address, date of birth, and/or Social Security number. Total affected: 236 individuals, including 1 Maine resident. Equifax 12-month identity monitoring offered to affected individuals. No indication data was actually exfiltrated or misused.
Maine clockDiscovered Jul 10, 2024 → Filed with AG Aug 14, 202435d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3dcbd416169b4c68New Hampshire State AGfiled 2024-08-19(5d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/4090b4ce-4528-4985-909c-3e0bc2649a95.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2024
- Raw hash
- 91b972d2b5e70b18d2a624d6cea68bf716496264226af7af5feab5e00364d913
Reporting entity
- Name
- Consolidated Brick & Building Supplies, Inc.norm: consolidated brick building supplies
- Industry
- Other Commercial
Victim entity
- Name
- Consolidated Brick & Building Supplies, Inc.norm: consolidated brick building supplies
- Industry
- Other Commercial
- Industry
- ManufacturingllmRetail & Consumerllm
Incident
- Discovered
- Jul 10, 2024
- Materiality determined
- —
- Notification sent
- Aug 14, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- ME AG >30d · 35d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jul 10, 2024→ Filed with AG: Aug 14, 202435d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.