DisclosureLens
MalwareManufacturingManufacturingRansomwareCapture Stored DataData ExfiltratedData EncryptedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountHealth (basic)PIIMediumContained

Hoffman Construction

bd_5f449c71e4d9a970 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 3, 2020

Filed

Nov 9, 2021

To disclose

15 months

Affected

44state residents only

Linked

3 filings

Confidence

63%
Full breach record for Hoffman Construction2 incidents on file

Hoffman Construction Company experienced a cybersecurity incident in August 2020 involving ransomware that encrypted systems and led to unauthorized access and file removal. The breach affected individuals' names, SSNs, driver's license numbers, financial account info, passport numbers, payment card info, and limited medical/health insurance information. The company engaged forensic investigators, secured its network, and offered one year of Experian IdentityWorks credit monitoring to affected individuals.

Incident timeline

undetected · 3 days
discovery → filing · 15 months / 463 days

Jul 31, 2020

Begins

Aug 3, 2020

Discovered

Nov 9, 2021

Filed

vs. sector median

+55 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Washington State AGNov 9 · first
Montana State AGNov 9 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.