HackingIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
All American Poly
bd_7ac6d67bf0290f98 · schema v1 · pii pii-v1
Full breach record for All American Poly →All American Poly Corp., a poly manufacturer in New Jersey, notified the Maryland Attorney General of a data security incident occurring on or around August 26, 2024. An unauthorized third party attempted to enter the network and exfiltrate data, potentially accessing names and Social Security numbers. One Maryland resident was notified on January 27, 2025. The company engaged forensic investigators, secured its network, and offered 12 months of credit monitoring and identity theft recovery services.
Leak gap clock✗ Leak >180d15 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
A leak claim by ransomhub about this victim predates this filing by 450 days.View originating leak claim
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376249.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 7ad27d0626423809085b020e8ccb249e795ca03123964ae8bde0f643048c4814
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- All American Polynorm: all american poly
- Domain
- allamericanpoly.com
- Industry
- manufacturing
Incident
- Discovered
- Aug 26, 2024
- Materiality determined
- —
- Notification sent
- Jan 27, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notification of Data Security Incident submitted to Maryland Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 months(444 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.