HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMINORMediumContained
Marten Transport
bd_75003077209ce0c2 · schema v1 · pii pii-v1
Full breach record for Marten Transport →Marten Transport, Ltd. notified California regulators of a breach occurring between September 30 and October 4, 2021. An unknown actor accessed systems, viewing or downloading names and potentially government IDs or financial data. The company disconnected systems, reported to federal law enforcement, and offered Equifax credit monitoring. The incident status is contained.
California clockDiscovered Oct 3, 2021 → Notified Mar 8, 2022156d ✗ CA 60-day late25 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
A leak claim by hive about this victim predates this filing by 59 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_e0f4910c3b69bea6Leak Sitehivefiled 2022-01-25(59d gap)Verified by operator
Regulatory filings (4) · sorted by filing gap
- bd_0f5a485357deeba5Montana State AGfiled 2022-03-25Verified by operator
- bd_8ad44bdc97b0f78bWashington State AGfiled 2022-03-25Verified
- bd_d7f0daa4522142acOregon State AGfiled 2022-03-25Verified by operator
- bd_ea74d9258957437fMaine State AGfiled 2022-03-25Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551995
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2022
- Raw hash
- 6da99a844410b3e8e18ce934c2ddd9d2957a14fd24dd119ae29ff6db8fb38cd3
Reporting entity
- Name
- Marten Transportnorm: marten transport
Victim entity
- Name
- Marten Transportnorm: marten transport
Incident
- Discovered
- Oct 3, 2021
- Materiality determined
- —
- Notification sent
- Mar 8, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported event to federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(173 days from discovery to filing)
- Compliance flags
- CA 60-day late · 156dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 3, 2021→ Notified: Mar 8, 2022156d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.