HackingStolen CredentialsEmployee Data InvolvedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
American Freight, LLC and its related subsidiaries and affiliates, including American Freight Outlet
bd_764d649a06acac7d · schema v1 · pii pii-v1
Full breach record for American Freight, LLC and its related subsidiaries and affiliates, including American Freight Outlet →American Freight experienced unauthorized access to a small number of employee email accounts between November 24, 2020, and December 9, 2020. The investigation determined that an unauthorized person had access to the contents of the accounts. On June 11, 2021, the company determined that emails or attachments contained personal information for affected individuals. The company secured the accounts, investigated the scope, and offered one year of complimentary identity monitoring through Kroll. No specific count of affected individuals was disclosed in the notice.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5016a4461ec8568dOregon State AGfiled 2021-08-24Candidate
- bd_8e8730d03621f181Maine State AGfiled 2021-08-24Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-544213
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2021
- Raw hash
- 21347c0995674f0a270420096c40b3d97c10ec0d8ffdf7863ee5ecfd6b1bbaf7
Reporting entity
- Name
- American Freight, LLC and its related subsidiaries and affiliates, including American Freight Outletnorm: american freight llc and its related subsidiaries and affiliates including american freight outlet
Victim entity
- Name
- American Freight, LLC and its related subsidiaries and affiliates, including American Freight Outletnorm: american freight llc and its related subsidiaries and affiliates including american freight outlet
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 11, 2021
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.