HackingIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Westlake Hardware, Inc.
bd_9a913dcdcabfb37c · schema v1 · pii pii-v1
Full breach record for Westlake Hardware, Inc. →Westlake Hardware, Inc. reported a data breach affecting systems between August 21-30, 2020, discovered on August 26, 2020. An unknown actor accessed systems containing names, SSNs, driver's licenses, financial accounts, and limited medical info. Westlake engaged forensic specialists, notified law enforcement, and offered 12 months of TransUnion credit monitoring. Notifications were sent starting January 22, 2021.
California clockDiscovered Aug 26, 2020 → Notified Jan 22, 2021149d ✗ CA 60-day late24 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_02c7c44b560b146dMaine State AGfiled 2021-02-10Candidate
- bd_119ec99d5b01787aMontana State AGfiled 2021-02-10Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-537895
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 10, 2021
- Raw hash
- e51da71699cb02bf847dc375e80c95b7e8db93c61f883133386f0092a4e9e035
Reporting entity
- Name
- Westlake Hardware, Inc.norm: westlake hardware
- Domain
- westlakehardware.com
- Industry
- retail_consumer
Victim entity
- Name
- Westlake Hardware, Inc.norm: westlake hardware
- Domain
- westlakehardware.com
- Industry
- retail_consumer
Incident
- Discovered
- Aug 26, 2020
- Materiality determined
- —
- Notification sent
- Jan 22, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- notified state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 weeks(168 days from discovery to filing)
- Compliance flags
- CA 60-day late · 149d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 26, 2020→ Notified: Jan 22, 2021149d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.