HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTPHIMediumContained
Expert Metal Finishing Solutions
bd_8010a5b7e074cd92 · schema v1 · pii pii-v1
Full breach record for Expert Metal Finishing Solutions →AOTCO Metal Finishing, LLC disclosed a cybersecurity incident discovered on March 27, 2026, where a threat actor potentially accessed and exfiltrated employee files containing SSNs, driver's license numbers, payroll, and health insurance info. AOTCO engaged forensic investigators, disabled the network and VPN, forced password resets, and offered 24 months of Experian IdentityWorks to affected employees.
Massachusetts clock⏱ MA AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_935c72dfcf3d60eeMassachusetts State AGfiled 2026-05-01Candidate
- bd_98d7cf312131d892New Hampshire State AGfiled 2026-05-12(11d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-744-aotco-metal-finishing-llc/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- 23c538cad875f116625817f5b4027768483f2d3b2b7bde91c65977999ed178f8
Reporting entity
- Name
- Expert Metal Finishing Solutionsnorm: expert metal finishing
- Domain
- aotco.com
Victim entity
- Name
- Expert Metal Finishing Solutionsnorm: expert metal finishing
- Domain
- aotco.com
Incident
- Discovered
- Mar 27, 2026
- Materiality determined
- —
- Notification sent
- May 6, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- notified government authorities of the incident
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- MA AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.