DisclosureLens
MalwareGovernmentGovernmentRansomwareData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Financial accountMediumContained

Automatic Funds Transfer Services, Inc.

bd_754c4ed2e84373a7 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 4, 2021

Filed

Mar 10, 2021

To disclose

5 weeks

Affected

23,935state residents only

Confidence

67%

Skagit PUD notified WA AG of a ransomware attack on third-party vendor AFTS on Feb 4, 2021. 23,935 customers notified on Feb 26. Potential exposure of names, addresses, account numbers, and bank routing/account numbers. AFTS engaged forensics and reported to FBI.

Washington clock WA AG >30d5 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 3 days
discovery → filing · 5 weeks / 34 days

Feb 1, 2021

Begins

Feb 4, 2021

Discovered

Mar 10, 2021

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed23,935 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.