MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICLowContained
American Associated Pharmacies
bd_5752d2fa56e1021f · schema v1 · pii pii-v1
Full breach record for American Associated Pharmacies →American Associated Pharmacies experienced a ransomware incident in October 2024. Unauthorized access began on October 13, 2024, and was detected on October 23, 2024, when suspicious activity including system encryption was observed. The attacker exfiltrated data, potentially impacting names and other personal information. The company contained the incident, engaged forensic experts, notified law enforcement, and is offering credit monitoring to affected individuals.
California clockDiscovered Oct 23, 2024 → Notified Nov 11, 2025384d ✗ CA 60-day late13 months discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_026dc026d7edd520Leak Siteembargofiled 2024-11-12(364d gap)Verified
Regulatory filings (4) · sorted by filing gap
- bd_6f03581859047e74Maine State AGfiled 2025-11-12Candidate
- bd_740593241b9440ecVermont State AGfiled 2025-11-12Verified
- bd_a055985a15fb12b5Montana State AGfiled 2025-11-12Verified
- bd_fe8758ed5a20a130Washington State AGfiled 2025-11-12Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-614123
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 12, 2025
- Raw hash
- e26c1397fee4e69ce987d424bde92690125a228c18d062915ff6922bfbab4870
Reporting entity
- Name
- American Associated Pharmaciesnorm: american associated pharmacies
Victim entity
- Name
- American Associated Pharmaciesnorm: american associated pharmacies
Incident
- Discovered
- Oct 23, 2024
- Materiality determined
- —
- Notification sent
- Nov 11, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reporting this Incident to relevant government agencies
Compliance
- Time to disclose
- 13 months(385 days from discovery to filing)
- Compliance flags
- CA 60-day late · 384dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 23, 2024→ Notified: Nov 11, 2025384d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.