HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICLowContained
Maritz Holdings Inc.
bd_4a5a64bea2308189 · schema v1 · pii pii-v1
Full breach record for Maritz Holdings Inc. →Maritz Holdings Inc. disclosed that an unauthorized third-party exploited a previously unknown vulnerability in Oracle E-Business Suite to access and exfiltrate files between August 10 and August 13, 2025. The company became aware of the incident in November 2025. Affected data includes names and other personal information. Maritz engaged forensic experts, notified law enforcement, and is offering 24 months of credit monitoring.
California clockDiscovered Nov 1, 2025 → Notified Feb 27, 2026118d ✗ CA 60-day late17 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_438cba26c14312fdLeak Sitecl0pfiled 2025-11-13(105d gap)Candidate
Regulatory filings (5) · sorted by filing gap
- bd_511e8774e8b05d7cIndiana State AGfiled 2026-02-27Verified by operator
- bd_c572b0fed3fddb00Vermont State AGfiled 2026-02-27Verified
- bd_e6494ae402d92dcdMaine State AGfiled 2026-02-27Verified
- bd_d6f87f82bc65a8ebCalifornia State AGfiled 2026-04-03(35d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 38d gap
- bd_19465167e1507b6bTexas State AGfiled 2026-04-06(38d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619475
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2026
- Raw hash
- a71a7d6d8e3dae00b438f7c3d432717abe7b9325a05d1abd39cba0393601d5cc
Reporting entity
- Name
- Maritz Holdings Inc.norm: maritz holdings
- Domain
- maritz.com
Victim entity
- Name
- Maritz Holdings Inc.norm: maritz holdings
- Domain
- maritz.com
Incident
- Discovered
- Nov 1, 2025
- Materiality determined
- —
- Notification sent
- Feb 27, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(118 days from discovery to filing)
- Compliance flags
- CA 60-day late · 118dLeak >90dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 1, 2025→ Notified: Feb 27, 2026118d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Feb 27, 2026→ AG copy submitted: Feb 27, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.