HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENTMediumActive
Norwex
bd_a1472ffc68e8a6dd · schema v1 · pii pii-v1
Full breach record for Norwex →Norwex USA, Inc. disclosed a data breach occurring around December 11, 2024, discovered on December 15, 2024. Unauthorized access to systems containing personal data (SSNs, driver's licenses, payroll, DOB, addresses) was identified. The company engaged outside experts, notified law enforcement, restricted access, and enhanced security protocols. Identity monitoring services were offered to affected individuals.
Vermont clock✓ VT AG ≤14 bday8 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5c51d17b454271e6Montana State AGfiled 2024-12-23Candidate
- bd_6198b292f3b745acDelaware State AGfiled 2024-12-23Verified
- bd_93976078e01ae927Oregon State AGfiled 2024-12-23Verified
- bd_a53ee30642d96d86Indiana State AGfiled 2024-12-23Verified
Show 1 more filing ↓Show fewer ↑
- bd_f0c63b26630217aeCalifornia State AGfiled 2024-12-23Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-12-23-norwex-usa-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2024
- Raw hash
- 0db2543e8c2701ca2d12ae0791129611272adc5774f04a08d171232657040cc3
Reporting entity
- Name
- Norwexnorm: norwex
- Domain
- norwex.com
Victim entity
- Name
- Norwexnorm: norwex
- Domain
- norwex.com
Incident
- Discovered
- Dec 15, 2024
- Materiality determined
- —
- Notification sent
- Dec 23, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the issue to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.