Avery Products Corporation
bd_9f8cfdfd51be813c · schema v1 · pii pii-v1
Full breach record for Avery Products Corporation →4 incidents on fileAvery Products Corporation experienced a ransomware attack affecting its website avery.com between July 18, 2024, and December 9, 2024. The company became aware of the incident on December 9, 2024. An unauthorized actor inserted malicious software to scrape credit card information, including CVV numbers and expiration dates, as well as names, addresses, and contact details. While initial evidence did not show exfiltration, subsequent reports of fraudulent charges suggest data may have been acquired. Avery engaged forensic experts, notified regulators, and is offering 12 months of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 18, 2024
Begins
Dec 9, 2024
Discovered
Jan 16, 2025
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Oregon State AGbd_0133914d5cd708f92025-01-16Verified
- Indiana State AGbd_9622529b26f17acf2025-01-16Verified
- Nebraska State AGbd_2bd3010a496522722025-01-15 · +1dVerified
- Delaware State AGbd_d2db253e180f71952025-01-15 · +1dVerified
Show 6 more filings ↓Show fewer ↑up to 26d gap
- New Hampshire State AGbd_c0cb72b951b7a3ed2025-01-13 · +3dVerified
- Vermont State AGbd_17d3515f645117e92025-01-29 · +13dVerified
- New Hampshire State AGbd_7c5c23e82caf557c2025-02-05 · +20dVerified
- Maine State AGbd_b9944af515ad8d512025-02-06 · +21dVerified
- Montana State AGbd_a2e5641bcdbf5b892025-02-07 · +22dVerified
- California State AGbd_a6b982179a1d1f962025-02-11 · +26dVerified
Showing first 10 of 13 linked disclosures.
Filing propagation · 11 filings · 9 states
View merged incident ↗Pattern: first filing Jan 13 (NH), last Feb 11 (CA) — a 29-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 13 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.