MalwareRetail & ConsumerRetailRansomwareCapture Stored DataData ExfiltratedData EncryptedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Hyper Ice, Inc.
bd_a3c360b3824c8dcf · schema v1 · pii pii-v1
Full breach record for Hyper Ice, Inc. →On June 25, 2024, Hyper Ice, Inc. (Hyperice) was alerted by its endpoint detection and response solution to attempted encryption on one system. A forensic investigation determined certain files may have been exfiltrated. Data mining concluded December 3, 2024, identifying first name, last name, and Social Security numbers as impacted. 58 Maryland residents were notified December 12, 2024, and offered 12 months of credit monitoring through TransUnion. Hyperice implemented MFA and strengthened password requirements.
Maryland clock✗ MD AG >90d23 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed58 affectedView incident
A leak claim by play about this victim predates this filing by 693 days.View originating leak claim
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376121.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 19, 2026
- Raw hash
- b4d7657c28bd2d5678b1762f622efa50ec5722042c564b8bcf2ba7322134fda4
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- Hyper Ice, Inc.norm: hyper ice
- Domain
- hyperice.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Jun 25, 2024
- Materiality determined
- —
- Notification sent
- Dec 12, 2024
- Affected individuals
- 58
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General
Compliance
- Time to disclose
- 23 months(693 days from discovery to filing)
- Compliance flags
- MD AG >90dLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.