Bacon Universal
bd_aa8748171d1ff2e0 · schema v1 · pii pii-v1
Full breach record for Bacon Universal →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Cactus on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Bacon Universal Company, Inc. has proudly served Hawaii's Construction Industry for more than 60 years.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Aug 22, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_243ec80b466568002024-02-23 · +185dCandidate
- Indiana State AGbd_345fdbd6b94bc63e2024-02-23 · +185dVerified
- Hawaii State AGbd_81e3595af88ee6d42024-02-23 · +185dVerified by operator
- Maine State AGbd_bd07f3875efa1c732024-02-23 · +185dVerified by operator
Show 1 more filing ↓Show fewer ↑up to 185d gap
- Massachusetts State AGbd_d767a1db669f83922024-02-23 · +185dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Aug 22, last Feb 23 (MA) — a 185-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
cactus
According to ransomware.live, The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure. There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox. Source: https://github.com/crocodyli/ThreatActors-TTPs