HackingTransportation & LogisticsTransportationCapture Stored DataData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Overseas Shipholding Group, Inc.
bd_700f147321d34c86 · schema v1 · pii pii-v1
Full breach record for Overseas Shipholding Group, Inc. →Overseas Shipholding Group, Inc. (OSG) experienced unauthorized access to certain computer systems on August 5, 2024. An unauthorized actor accessed and/or took files containing names, Social Security numbers, passport numbers, Merchant Mariner credential numbers, and/or Transportation Worker identification credential information. OSG secured involved systems, conducted an investigation concluding October 28, 2024, and offered one year of Equifax credit monitoring to affected individuals.
Leak gap clock⏱ Leak >90d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 4 about the same incident.View merged incident
A leak claim by ransomhub about this victim predates this filing by 104 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0e1d268849e71eefMaine State AGfiled 2024-12-02Candidate
- bd_4572f9d6af857adaVermont State AGfiled 2024-12-02Verified
- bd_f56f78da8d95bfa4New Hampshire State AGfiled 2024-12-02Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-595514
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 2, 2024
- Raw hash
- c72ebe0818e996ae8522eb2732b8980cb2529c3fd9b441a1a55f09080a8cb13c
Reporting entity
- Name
- Overseas Shipholding Group, Inc.norm: overseas shipholding
- Domain
- osg.com
Victim entity
- Name
- Overseas Shipholding Group, Inc.norm: overseas shipholding
- Domain
- osg.com
- Industry
- Transportation & Logisticsllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Compliance flags
- Leak >90d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.