MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Penhall Company
bd_78af2fa31cdd1e78 · schema v1 · pii pii-v1
Full breach record for Penhall Company →Penhall Company experienced a ransomware incident on December 28, 2022, where systems were encrypted. An unauthorized individual accessed a computer system containing personal information, including names, Social Security numbers, and driver's license numbers. The company secured systems, initiated an investigation, and offered identity theft protection services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_4de776dec448f0b6Maine State AGfiled 2023-02-15Verified
- bd_b0031b1b7ef3c4fdMontana State AGfiled 2023-02-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-563245
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2023
- Raw hash
- 78896bd855d556a75ba0d055aa18d022bf7660421ecd418b3e62c65a72b73c9f
Reporting entity
- Name
- Penhall Companynorm: penhall
Victim entity
- Name
- Penhall Companynorm: penhall
Incident
- Discovered
- Dec 28, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.