MalwareRansomwareData EncryptedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Ampex Data Systems
bd_5a80584f7d8fe5e9 · schema v1 · pii pii-v1
Full breach record for Ampex Data Systems →Ampex Data Systems Corporation experienced a ransomware incident on March 21, 2026, where a threat actor accessed and encrypted the network at one office location. The incident affected current and former contractors, employees, and dependents, potentially exposing names, addresses, social security numbers, dates of birth, and in limited cases, driver's license or banking information. The company contained the incident on March 23, 2026, and is offering 12 months of credit monitoring and fraud assistance.
Leak gap clock⏱ Leak >90d10 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_571e436d5a1335c1Leak Siteplayfiled 2026-03-30(57d gap)Verified
- bd_cde8e1e1cbada45fLeak Siteplayfiled 2026-01-12(135d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_6c8fa41d68c17607Maine State AGfiled 2026-05-18(9d gap)Verified by operator
- bd_68635f5ae613817aMassachusetts State AGfiled 2026-05-01(26d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-623996
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 27, 2026
- Raw hash
- 2e163bca235bec3eed97d0601cfa4a54ff57ccf1e7c8ec0dd37557e4471d2e7f
Reporting entity
- Name
- Ampex Data Systemsnorm: ampex data
- Domain
- ampex.com
Victim entity
- Name
- Ampex Data Systemsnorm: ampex data
- Domain
- ampex.com
Incident
- Discovered
- Mar 21, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI’s Internet Crime Complaint Center (IC3)Notified the Department of Defense Cyber Crime Center (DC3)
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.