MalwareRansomwareRansom DemandedData EncryptedEmployee Data InvolvedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIALMediumContained
Anellotech Inc.
bd_50dedff0551ca0da · schema v1 · pii pii-v1
Full breach record for Anellotech Inc. →Anellotech Inc. (Pearl River, NY) experienced a ransomware attack discovered on January 13, 2025, with the breach occurring on December 24, 2024. Affected employee data included names, addresses, dates of birth, Social Security numbers, passport/driver's license information, and banking information. 184 individuals were affected in total; 3 were Maine residents. Experian IdentityWorks (24-month) credit monitoring was offered to affected individuals.
Maine clockDiscovered Jan 13, 2025 → Filed with AG Feb 21, 202539d ⏱ ME AG >30d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_69bba68fe749d70cMaryland State AGfiled 2025-02-22(1d gap)Verified
- bd_2ef79b670c74c86aVermont State AGfiled 2025-02-26(5d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/7edf300b-bbfa-4f88-8b53-50f55a4b1c31.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 21, 2025
- Raw hash
- 232266f925dbd12f913a0b14d92eae8b5ca958b731591ba1fcaff56f5272201b
Reporting entity
- Name
- Anellotech Inc.norm: anellotech
- Industry
- Other Commercial
Victim entity
- Name
- Anellotech Inc.norm: anellotech
- Industry
- Other Commercial
Incident
- Discovered
- Jan 13, 2025
- Materiality determined
- —
- Notification sent
- Feb 26, 2025
- Affected individuals
- 3
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Communicated with law enforcement
Compliance
- Time to disclose
- 6 weeks(39 days from discovery to filing)
- Compliance flags
- ME AG >30d · 39d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 13, 2025→ Filed with AG: Feb 21, 202539d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.