HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumActive
Norwex
bd_6198b292f3b745ac · schema v1 · pii pii-v1
Full breach record for Norwex →Norwex USA, Inc. disclosed a security breach occurring around December 11, 2024, discovered on December 15, 2024. An unauthorized person accessed systems containing personal data, including SSNs, driver's licenses, payroll, and tax forms. Norwex activated incident response protocols, engaged outside experts, notified law enforcement, and restricted system access. Affected individuals were offered two years of complimentary identity monitoring through Identity Defense. The notification covers US residents, with specific instructions for Massachusetts.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5c51d17b454271e6Montana State AGfiled 2024-12-23Candidate
- bd_93976078e01ae927Oregon State AGfiled 2024-12-23Verified
- bd_a1472ffc68e8a6ddVermont State AGfiled 2024-12-23Verified
- bd_a53ee30642d96d86Indiana State AGfiled 2024-12-23Verified
Show 1 more filing ↓Show fewer ↑
- bd_f0c63b26630217aeCalifornia State AGfiled 2024-12-23Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/12/FINAL-2024-12-23-US-not-MA-Notification-to-Data-Subjects.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2024
- Raw hash
- cbcdf12f08c80548c46ce727857083d5c977b8de1d18555f6005f0759e0d0f05
Reporting entity
- Name
- Norwexnorm: norwex
- Domain
- norwex.com
Victim entity
- Name
- Norwexnorm: norwex
- Domain
- norwex.com
Incident
- Discovered
- Dec 15, 2024
- Materiality determined
- —
- Notification sent
- Dec 23, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the issue to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.