MalwareRansomwareRansom DemandedData ExfiltratedPIIIDENTITY_BASICLowContained
MW Components
bd_961842e4dc0b2aad · schema v1 · pii pii-v1
Full breach record for MW Components →MW Components disclosed a ransomware attack discovered on March 26, 2023, involving unauthorized access between March 1-26, 2023. The incident resulted in the potential exfiltration of personal information (PII). The company engaged forensic investigators, notified law enforcement, and offered one year of Experian IdentityWorks credit monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday22 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
A leak claim by blacksuit about this victim predates this filing by 132 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5cf56f6afff3cbc6Maine State AGfiled 2023-08-29(1d gap)Verified
- bd_e09ff3bc5f2bd8f2California State AGfiled 2023-08-29(1d gap)Candidate
- bd_5ee69a804aecb547New Hampshire State AGfiled 2023-08-30(2d gap)Candidate
- bd_dce2bfbf462b0778New Hampshire State AGfiled 2023-08-01(27d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 31d gap
- bd_2f2ea2a07ebd3549California State AGfiled 2023-07-28(31d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-28-mw-components-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2023
- Raw hash
- caed0ba2f35cb26427bea68040326893046574944064365b4b51a7fb89676f8d
Reporting entity
- Name
- MW Componentsnorm: mw components
- Domain
- mwcomponents.com
Victim entity
- Name
- MW Componentsnorm: mw components
- Domain
- mwcomponents.com
Incident
- Discovered
- Mar 26, 2023
- Materiality determined
- Mar 26, 2023
- Notification sent
- Aug 28, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 22 weeks(155 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.