MalwareRansomwarePhishingData EncryptedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
HEAVY
bd_5b7ce0bb4fc71b55 · schema v1 · pii pii-v1
Full breach record for HEAVY →Heavy Hammer, Inc. experienced a ransomware attack on April 21, 2023, following a phishing campaign targeting employees. The incident compromised customer data including names, contact information, and payment card/bank account details. The company contained the attack, engaged forensic experts, and is offering 12 months of identity monitoring to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_f0a7a07d987e77a1Oregon State AGfiled 2023-06-06Verified
- bd_5b0383fe9134555aMontana State AGfiled 2023-06-02(4d gap)Verified
- bd_720d1e34f4ace793Vermont State AGfiled 2023-06-02(4d gap)Verified
- bd_32d7a0ae4bfbd447Washington State AGfiled 2023-05-23(14d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567668
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 6, 2023
- Raw hash
- aea3f3e8f7b8c06d4782b2a5b0b91be8923cd3990e07e506190e5549aa325f4c
Reporting entity
- Name
- HEAVYnorm: heavy
Victim entity
- Name
- HEAVYnorm: heavy
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 6, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1566 PhishingT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.