HackingData ExfiltratedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
HALO Branded Solutions
bd_7bee031c58bc1b87 · schema v1 · pii pii-v1
Full breach record for HALO Branded Solutions →HALO Branded Solutions experienced a security incident in November 2023 where a sophisticated threat actor accessed computer systems containing personnel records. The actor acquired files containing names, dates of birth, and Social Security numbers. HALO detected suspicious activity on November 22, 2023, took systems offline, and engaged law enforcement and cybersecurity experts. Notification was sent on March 28, 2024, after confirming the scope of affected data. 12 months of identity protection services are being offered to affected individuals.
California clockDiscovered Nov 22, 2023 → Notified Mar 28, 2024127d ✗ CA 60-day late19 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1819f5a4c81a0228Maine State AGfiled 2024-04-01Candidate
- bd_c2daea65d710a2caMontana State AGfiled 2024-04-01Verified
- bd_0357f80769d215c4Indiana State AGfiled 2024-03-28(4d gap)Verified
- bd_9991d6b8ac407bd9Vermont State AGfiled 2024-03-28(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-583354
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 1, 2024
- Raw hash
- 953522d592967f3c5dc5ea2ce5187541d801e5cd67d54efb47d105ef5a9ffcab
Reporting entity
- Name
- HALO Branded Solutionsnorm: halo branded
- Domain
- halo.com
Victim entity
- Name
- HALO Branded Solutionsnorm: halo branded
- Domain
- halo.com
Incident
- Discovered
- Nov 22, 2023
- Materiality determined
- —
- Notification sent
- Mar 28, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 19 weeks(131 days from discovery to filing)
- Compliance flags
- CA 60-day late · 127d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 22, 2023→ Notified: Mar 28, 2024127d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.