HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
AIS Inc
bd_7cff3a58df38cce4 · schema v1 · pii pii-v1
Full breach record for AIS Inc →AIS InfoSource LP reported unauthorized access to its network between February 16-21, 2025, discovered on February 17, 2025. An external actor exfiltrated a limited subset of data including names, Social Security numbers, and financial account information. The company engaged forensic specialists, secured the network, and is offering credit monitoring. This is a supplemental notice.
California clockDiscovered Feb 17, 2025 → Notified Jun 13, 2025116d ✗ CA 60-day late28 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_12b45644bcfa9d13Montana State AGfiled 2025-08-29Candidate
- bd_545aa9b9cb26e2a4Texas State AGfiled 2025-09-04(6d gap)Verified
- bd_0504c046ba35e9a6New Hampshire State AGfiled 2025-07-21(39d gap)Verified
- bd_ac840f7499b9ded1California State AGfiled 2025-07-21(39d gap)Candidate
Show 4 more filings ↓Show fewer ↑up to 60d gap
- bd_1953d698d62e8e4dVermont State AGfiled 2025-06-30(60d gap)Verified
- bd_75bd756c8f7a12aeCalifornia State AGfiled 2025-06-30(60d gap)Verified
- bd_c2fcdb77a103f364New Hampshire State AGfiled 2025-06-30(60d gap)Verified
- bd_ef63887c32401b4eIndiana State AGfiled 2025-06-30(60d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-607958
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2025
- Raw hash
- 54c6ce0dab8ae3abe803cfe1634ac8e37e6f45d4e4ba421d90e75c1b534d18a1
Reporting entity
- Name
- AIS Incnorm: ais
- Domain
- ais-inc.com
Victim entity
- Name
- AIS Incnorm: ais
- Domain
- ais-inc.com
Incident
- Discovered
- Feb 17, 2025
- Materiality determined
- —
- Notification sent
- Jun 13, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 28 weeks(193 days from discovery to filing)
- Compliance flags
- CA 60-day late · 116d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 17, 2025→ Notified: Jun 13, 2025116d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.