MalwareRansomwareData EncryptedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSEMPLOYMENTHEALTH_BASICCREDENTIALSMediumContained
MKS Instruments, Inc
bd_7ab949b29245ba5a · schema v1 · pii pii-v1
Full breach record for MKS Instruments, Inc →MKS Instruments, Inc. disclosed a ransomware incident discovered on February 13, 2023. The attack encrypted business and manufacturing systems. While exfiltration of personal employee data has not been confirmed, it cannot be ruled out. Potentially affected data includes names, contact info, SSNs, login credentials, bank account info, and health/employment data. The company activated incident response, engaged outside experts, notified law enforcement, and is offering 2 years of identity monitoring.
California clockDiscovered Feb 13, 2023 → Notified Feb 16, 20232d ✓ CA 60-day OK2 days discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_10609a6a1a76f030New Hampshire State AGfiled 2023-02-15Verified
- bd_40fb17ba9f50a304Maine State AGfiled 2023-02-16(1d gap)Candidate
- bd_488d1bfaf6139cd5Montana State AGfiled 2023-02-16(1d gap)Verified
- bd_91e20ee0c300cf70SEC 8-Kfiled 2023-02-13(2d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 9d gap
- bd_a88f0c343179b832SEC 8-Kfiled 2023-02-06(9d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-563255
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2023
- Raw hash
- aa27dc9f13afd3790aaee0d5138b0a394fb4a8d1310cb1e52e727445ef703772
Reporting entity
- Name
- MKS Instruments, Incnorm: mks instruments
- Domain
- mksinst.com
Victim entity
- Name
- MKS Instruments, Incnorm: mks instruments
- Domain
- mksinst.com
Incident
- Discovered
- Feb 13, 2023
- Materiality determined
- —
- Notification sent
- Feb 16, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSEMPLOYMENTHEALTH_BASICCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the issue to U.S. law enforcement
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 2d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 13, 2023→ Notified: Feb 16, 20232d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.