HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
ACUITY BRANDS LIGHTING, INC.
bd_9f481a0a57a510be · schema v1 · pii pii-v1
Full breach record for ACUITY BRANDS LIGHTING, INC. →Acuity Brands, Inc. reported a data security incident in California involving unauthorized access to its systems on October 6-7, 2020, and December 7-8, 2021. The breach exposed personal information including names, Social Security numbers, driver's license numbers, and financial account information, along with limited health information related to workers' compensation and FMLA. Acuity engaged a third-party cybersecurity firm, enhanced security protocols, and offered one year of Experian IdentityWorks to affected individuals.
Leak gap clock✗ Leak >180d52 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by conti about this victim predates this filing by 325 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_0808452fec3877d5Leak Sitecontifiled 2022-01-15(325d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_8343b9543b9f0798Maine State AGfiled 2022-12-06Verified by operator
- bd_e48270b605e5e4d5Montana State AGfiled 2022-12-06Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-559772
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 6, 2022
- Raw hash
- eda35bf80c9c6d4798e4dc68a7cc31a941abb8be9f38fb26e077e4395bb429e1
Reporting entity
- Name
- ACUITY BRANDS LIGHTING, INC.norm: acuity brands lighting
Victim entity
- Name
- ACUITY BRANDS LIGHTING, INC.norm: acuity brands lighting
Incident
- Discovered
- Dec 7, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 52 weeks(364 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.