MalwareRansomwareCapture Stored DataData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedTargetedPIIIDENTITY_BASICLowContained
LEONARD'S EXPRESS, INC.
bd_a083549c9b0dd53d · schema v1 · pii pii-v1
Full breach record for LEONARD'S EXPRESS, INC. →Leonard's Express notified New Hampshire and Rhode Island residents of a ransomware incident. Unauthorized access occurred between Nov 15 and Dec 2, 2023, with files encrypted and data acquired. Suspicious activity was discovered on Dec 2, 2023. PII, including names and addresses, was involved. The company engaged forensic specialists, notified law enforcement, and offered credit monitoring.
Leak gap clock✗ Leak >180d28 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 195 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_8970b461a80433e6Maine State AGfiled 2024-06-17Candidate
- bd_c2a7cc2031ddfa6eIndiana State AGfiled 2024-06-17Verified
- bd_f0e77f8ba90783ddMontana State AGfiled 2024-06-17Verified by operator
- bd_21d284cad313393eMaine State AGfiled 2024-06-18(1d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/leonards-express-20240617.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 17, 2024
- Raw hash
- bd0ce39e0b88c1ddbe40440ad7b0e76f22d49fdbb3dbbd650e31dba367d9d2e7
Reporting entity
- Name
- LEONARD'S EXPRESS, INC.norm: leonard s express
- Domain
- leonardsexpress.com
Victim entity
- Name
- LEONARD'S EXPRESS, INC.norm: leonard s express
- Domain
- leonardsexpress.com
Incident
- Discovered
- Dec 2, 2023
- Materiality determined
- May 10, 2024
- Notification sent
- Jun 17, 2024
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified federal law enforcement regarding the eventproviding written notice of this incident to relevant state regulators, as necessary, and to the three major credit reporting agencies
Compliance
- Time to disclose
- 28 weeks(198 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.