MalwareRansomwareCustomer Data InvolvedIDENTITY_GOVERNMENTMedium
YUM! Brands, Inc.
bd_670ffb1c99274f7f · schema v1 · pii pii-v1
Full breach record for YUM! Brands, Inc. →Yum! Brands, Inc. reported a ransomware attack that occurred on January 13, 2023, and was discovered on March 9, 2023. The breach affected 11 Maine residents, compromising their names and driver's license or non-driver identification card numbers. Impacted individuals were notified on April 7, 2023, and offered two years of identity protection services.
Maine clockDiscovered Mar 9, 2023 → Filed with AG Apr 7, 202329d ✓ ME AG ≤30d29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_05b2f3b76db7eda6Washington State AGfiled 2023-04-07Verified
- bd_17c063610aa17e65California State AGfiled 2023-04-13(6d gap)Verified
- bd_712a74721c6ee198New Hampshire State AGfiled 2023-04-13(6d gap)Verified
- bd_01aaa01480a1e00bOregon State AGfiled 2023-04-14(7d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 78d gap
- bd_48c445e8e34473fdMontana State AGfiled 2023-04-14(7d gap)Verified
- bd_edd346b972acb4e0Delaware State AGfiled 2023-04-14(7d gap)Verified
- bd_930c9d1e16f8cabcSEC 8-Kfiled 2023-01-19(78d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/b85bfcfb-4ff7-419e-8dd2-95e8f41a5ad1.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 7, 2023
- Raw hash
- 07956bc61148ca74df5ee1b947768e946ad5b4df222b203f62b96450bba293df
Reporting entity
- Name
- YUM! Brands, Inc.norm: yum brands
Victim entity
- Name
- YUM! Brands, Inc.norm: yum brands
Incident
- Discovered
- Mar 9, 2023
- Materiality determined
- —
- Notification sent
- Apr 7, 2023
- Affected individuals
- 11
- Data types
- IDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 29d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 9, 2023→ Filed with AG: Apr 7, 202329d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.