Carpenter Co.
bd_87407076f951eb8b · schema v1 · pii pii-v1
Full breach record for Carpenter Co. →2 incidents on fileCarpenter Co., a manufacturer of comfort cushioning products, experienced a ransomware incident on March 18, 2021, impacting its IT systems. The company did not pay the ransom. Forensic investigation confirmed on May 24, 2021, that a threat actor accessed personal information of employees and contractors, including names, dates of birth, and Social Security numbers. Five New Hampshire residents were affected. Carpenter contained the incident, removed malware, and is offering 12 months of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 18, 2021
Begins
Jul 29, 2021
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_d19122e30db7711c2021-07-28 · +1dVerified
- Montana State AGbd_446b8e72df69c9b32021-07-27 · +2dCandidate
- California State AGbd_4e3bd9c6373123282021-09-11 · +44dVerified
- Maine State AGbd_c6353158144d1d182021-09-11 · +44dVerified by operator
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 27 (MT), last Sep 11 (ME) — a 46-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.