Avery Products Corporation
bd_9f8cfdfd51be813c · schema v1 · pii pii-v1
Full breach record for Avery Products Corporation →Avery Products Corporation experienced a ransomware attack affecting its website avery.com between July 18, 2024, and December 9, 2024. The company became aware of the incident on December 9, 2024. An unauthorized actor inserted malicious software to scrape credit card information, including CVV numbers and expiration dates, as well as names, addresses, and contact details. While initial evidence did not show exfiltration, subsequent reports of fraudulent charges suggest data may have been acquired. Avery engaged forensic experts, notified regulators, and is offering 12 months of credit monitoring to affected individuals.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_0133914d5cd708f9Oregon State AGfiled 2025-01-16Verified
- bd_9622529b26f17acfIndiana State AGfiled 2025-01-16Verified
- bd_c0cb72b951b7a3edNew Hampshire State AGfiled 2025-01-13(3d gap)Verified
- bd_dc0171a2cb3b6587Maine State AGfiled 2025-01-13(3d gap)Candidate
Show 6 more filings ↓Show fewer ↑up to 26d gap
- bd_3fc44f2276bcd5a0Washington State AGfiled 2025-01-10(6d gap)Verified
- bd_17d3515f645117e9Vermont State AGfiled 2025-01-29(13d gap)Verified
- bd_7c5c23e82caf557cNew Hampshire State AGfiled 2025-02-05(20d gap)Verified
- bd_b9944af515ad8d51Maine State AGfiled 2025-02-06(21d gap)Verified
- bd_a2e5641bcdbf5b89Montana State AGfiled 2025-02-07(22d gap)Verified
- bd_a6b982179a1d1f96California State AGfiled 2025-02-11(26d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-597433
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 16, 2025
- Raw hash
- fcf9515b3bb63439f5e7f205051e74667ea953cdda829e93f070c304fa2c4de0
Reporting entity
- Name
- Avery Dennison Corpnorm: avery dennison
- Domain
- averydennison.com
Victim entity
- Name
- Avery Products Corporationnorm: avery products
- Domain
- avery.com
Incident
- Discovered
- Dec 9, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported to certain state regulators and Attorneys General
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.