DisclosureLens
HackingTechnologyManufacturingInformationStolen CredentialsData ExfiltratedEmployee Data InvolvedMulti-Stage ChainIdentity (basic)Government IDFinancial accountHealth (basic)EmploymentMediumContained

ACUITY BRANDS LIGHTING, INC.

bd_9f481a0a57a510be · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 7, 2021

Filed

Dec 6, 2022

To disclose

52 weeks

Affected

Not disclosed

Linked

6 filings

Confidence

64%
Full breach record for ACUITY BRANDS LIGHTING, INC.

Acuity Brands, Inc. disclosed two unrelated incidents of unauthorized access where an external actor copied files containing personal information. The first incident occurred Oct 6-7, 2020; the second Dec 7-8, 2021, when the company identified the breach. Affected data included names, SSNs, driver's license numbers, financial account info, and limited health/employment records. The company engaged third-party cybersecurity firms, secured systems, and offered one year of identity protection services.

Leak gap clock Leak >180d52 weeks discovery → filing

Incident timeline

undetected · 427 days
discovery → filing · 52 weeks / 364 days

Oct 6, 2020

Begins

Dec 7, 2021

Discovered

Dec 6, 2022

Filed

vs. sector median

+33 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Indiana State AGDec 6 · first
Maine State AGDec 6 · first
Montana State AGDec 6 · first
California State AGDec 6 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.