DisclosureLens
MalwareProfessional ServicesProfessional ServicesRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedFinancial accountIdentity (basic)Government IDPHIHealth (basic)HighContained

Cardinal Services

bd_aa2abd061d19d40b · schema v1 · pii pii-v1

Severity

High

Discovered

Jun 30, 2025

Filed

May 20, 2026

To disclose

46 weeks

Affected

2,066state residents only

Linked

4 filings

Confidence

70%
Full breach record for Cardinal Services5 incidents on file

Cardinal Services, Inc. experienced a ransomware cyberattack in Washington state. The breach occurred between June 30, 2025, and August 8, 2025, and was discovered on June 30, 2025. Approximately 2,066 individuals were affected, with data including names, SSNs, and financial account numbers exposed. The company offered 12 months of credit monitoring to victims.

Leak gap clock Leak >180d46 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 46 weeks / 324 days

Jun 30, 2025

Begins

Jun 30, 2025

Discovered

May 20, 2026

Filed

vs. sector median

+29 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Vermont State AGMay 20 · first
Indiana State AGMay 20 · first
Washington State AGMay 20 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.