MalwareGovernmentGovernmentRansomwareData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Financial accountMediumContained
Automatic Funds Transfer Services, Inc.
bd_754c4ed2e84373a7 · schema v1 · pii pii-v1
Skagit PUD notified WA AG of a ransomware attack on third-party vendor AFTS on Feb 4, 2021. 23,935 customers notified on Feb 26. Potential exposure of names, addresses, account numbers, and bank routing/account numbers. AFTS engaged forensics and reported to FBI.
J jump to incidentP pin to compareR raw source
Washington clock⏱ WA AG >30d5 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Incident timeline
undetected · 3 days
discovery → filing · 5 weeks / 34 days
Feb 1, 2021
Begins
Feb 4, 2021
Discovered
Mar 10, 2021
Filed
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed23,935 affectedView incident
Evidence ladder
Leak-site claim
Attacker assertion only. Establishes: claim date, group, alleged victim.
Press / market report
Unlocks: incident narrative, operational impact. Still no compliance clock.
State AG / regulator filingThis record
Unlocks: discovery date, data types, affected count, compliance clock.
SEC 8-K / victim statement
Unlocks: materiality, stated response, full audit trail. Ceiling removed.