MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Alpha Industries, Inc.
bd_7b839a7a8a9f571c · schema v1 · pii pii-v1
Full breach record for Alpha Industries, Inc. →Aptos, Inc., a third-party platform provider, experienced a data breach affecting Alpha Industries customers. The incident occurred between February 2016 and December 2016, involving malware placed on Aptos' servers. The breach exposed customer names, addresses, phone numbers, email addresses, and payment card numbers with expiration dates. No CVV, PIN, or SSN data was accessed. Aptos engaged cybersecurity firm Xandiant to remove malware and cooperated with federal law enforcement. Affected customers were offered one year of Equifax Credit Watch Silver monitoring.
California clockDiscovered Nov 1, 2016 → Notified Feb 6, 201797d ✗ CA 60-day late17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6d9248eda249913aWashington State AGfiled 2017-02-25Candidate
- bd_9ad577efe8b29430Oregon State AGfiled 2017-03-09(12d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66556
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 25, 2017
- Raw hash
- 6a5569b6235ad05d6a19f9f6a985144cc75f7d0eaa47b8c23220d88609521f15
Reporting entity
- Name
- Aptos Networknorm: aptos network
- Domain
- aptosnetwork.com
Victim entity
- Name
- Alpha Industries, Inc.norm: alpha industries
- Industry
- retail_consumer
Incident
- Discovered
- Nov 1, 2016
- Materiality determined
- —
- Notification sent
- Feb 6, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Cooperating with federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- CA 60-day late · 97d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 1, 2016→ Notified: Feb 6, 201797d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.