MalwareRetail & ConsumerRetailRansomwareRansom DemandedData EncryptedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTPIIMediumContained
HANESBRANDS INC.
bd_77190cfcd636f76f · schema v1 · pii pii-v1
Full breach record for HANESBRANDS INC. →On May 24, 2022, HanesBrands detected a ransomware incident impacting certain internal IT systems. The company contained the incident, reported it to law enforcement, and conducted a data review that identified potentially impacted personal information including contact information, date of birth, financial account information, government-issued ID numbers (SSN, driver's license, passport), and limited employment-related health information. Affected individuals were offered two years of complimentary Experian IdentityWorks credit monitoring.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_1bff8c804887df1dNew Hampshire State AGfiled 2022-11-29Verified
- bd_c9aa4e72eaff47ccOregon State AGfiled 2022-11-29Verified
- bd_6bad099dc259b08fMaine State AGfiled 2022-11-30(1d gap)Verified
- bd_416bfab051b743caWashington State AGfiled 2022-11-23(6d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 105d gap
- bd_8c1ac18743a5161dOregon State AGfiled 2022-09-30(60d gap)Verified
- bd_9fb9627acb7eb000Montana State AGfiled 2022-08-16(105d gap)Candidate
- bd_f71ffedbeab73a05California State AGfiled 2022-08-16(105d gap)Verified
- bd_f9d4220f22ced5eeMaine State AGfiled 2022-08-16(105d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-559566
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 29, 2022
- Raw hash
- 8d74b0001be7f7dd2934b083685a9cdb2e6ef3bc96b8542710be7d362790711e
Reporting entity
- Name
- HANESBRANDS INC.norm: hanesbrands
Victim entity
- Name
- HANESBRANDS INC.norm: hanesbrands
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Aug 16, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.