MalwareRansomwareThe Dark OverlordData EncryptedRansom DemandedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
USA Hoist Company, Inc., Mid-American Elevator Company, Inc., and Mid-American Elevator Equipment Company, Inc.
bd_a2f95e48b76d05ef · schema v1 · pii pii-v1
Full breach record for USA Hoist Company, Inc., Mid-American Elevator Company, Inc., and Mid-American Elevator Equipment Company, Inc. →USA Hoist Company, Mid-American Elevator Company, and Mid-American Elevator Equipment Company experienced a ransomware attack on October 17, 2017, attributed to the group 'the Dark Overlord'. The attack encrypted data systems containing employee and vendor information, including names, addresses, Social Security numbers, bank account details, and health insurance applications. The company engaged forensic investigators and notified the FBI and state Attorneys General.
California clockDiscovered Oct 17, 2017 → Notified Nov 14, 201728d ✓ CA 60-day OK5 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-112319
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2017
- Raw hash
- 10e20d103a5af0d01ebcf66780c1ffb5bed5d01741b6e17c46c063c5d2358deb
Reporting entity
- Name
- USA Hoist Company, Inc., Mid-American Elevator Company, Inc., and Mid-American Elevator Equipment Company, Inc.norm: usa hoist company inc mid american elevator company inc and mid american elevator equipment
Victim entity
- Name
- USA Hoist Company, Inc., Mid-American Elevator Company, Inc., and Mid-American Elevator Equipment Company, Inc.norm: usa hoist company inc mid american elevator company inc and mid american elevator equipment
Incident
- Discovered
- Oct 17, 2017
- Materiality determined
- —
- Notification sent
- Nov 14, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Ransomware· the Dark Overlord
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- The Dark OverlordExternalFinancial
- Regulator citations
- Notified applicable states' Attorneys GeneralFBI visited our offices to inform us that we may become the subject of such an attack
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 28d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 17, 2017→ Notified: Nov 14, 201728d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.