MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSMediumContained
PEPSI BOTTLING VENTURES LLC
bd_7e0e207c77db2124 · schema v1 · pii pii-v1
Full breach record for PEPSI BOTTLING VENTURES LLC →Pepsi Bottling Ventures LLC disclosed a security incident where an unknown party accessed internal IT systems on or around December 23, 2022, installed malware, and downloaded information. The company discovered the activity on January 10, 2023, and contained the breach by January 19, 2023. Affected data included names, addresses, government IDs (SSN, driver's license), financial account info, and limited medical history. The company reported to law enforcement, suspended systems, reset passwords, and engaged Kroll for one year of identity monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_087ee3d4909d5ff8Montana State AGfiled 2023-02-10Verified
- bd_457f712221ffd4c9Montana State AGfiled 2023-02-10Candidate
- bd_a05eb7d77f61534eDelaware State AGfiled 2023-02-10Verified
- bd_c403cc818fe00f72Vermont State AGfiled 2023-02-10Verified
Show 2 more filings ↓Show fewer ↑up to 10d gap
- bd_fce79404f1064390Delaware State AGfiled 2023-02-10Verified
- bd_44bd24affb7ea5dbMaine State AGfiled 2023-02-20(10d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/Exhibit-A-to-AsG-Letters-PBV-Sample-Notice-CM-12-Mo10895445.3.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 10, 2023
- Raw hash
- 7ad8b7e98691fa184bcfb987ee064b0975e5d8fe96df0961b043a7cebefaf762
Reporting entity
- Name
- PEPSI BOTTLING VENTURES LLCnorm: pepsi bottling
Victim entity
- Name
- PEPSI BOTTLING VENTURES LLCnorm: pepsi bottling
Incident
- Discovered
- Jan 10, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.