DisclosureLens
MalwareHealthcareHealthcareRansomwareRansom DemandedData ExfiltratedCustomer Data InvolvedIdentity (basic)MediumActive

ACE Surgical Supply Co., Inc.

bd_ae9758955294443b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 29, 2021

Filed

Oct 12, 2021

To disclose

15 weeks

Affected · nationwide

3,57428 in this filing

Linked

8 filings

Confidence

50%
Full breach record for ACE Surgical Supply Co., Inc.3 incidents on file

On June 29, 2021, ACE Surgical Supply Co., Inc. discovered it was the victim of a ransomware cyberattack in which company files were accessed without authorization. The company secured its systems, contacted the FBI, and began an investigation. An initial notification was sent on July 28, 2021, to three affected Maine residents. In September 2021, the investigation identified an additional 25 affected customers who are Maine residents. The compromised customer information included names, contact information, and DEA and physician state license numbers. A second round of written notifications, including an offer for credit monitoring services, was sent to affected Maine residents on October 6, 2021. The investigation is ongoing, and there is no evidence that the compromised information has been made public or used for identity theft.

Maine clockDiscovered Jun 29, 2021Filed with AG Oct 12, 2021105d ME AG >90d15 weeks discovery → filing

Incident timeline

discovery → filing · 15 weeks / 105 days

Jun 29, 2021

Begins

Jun 29, 2021

Discovered

Oct 12, 2021

Filed

vs. sector median

+4 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 76d gap

Filing propagation · 8 filings · 5 states

View merged incident ↗
Maine State AGJul 28 · first
New Hampshire State AGJul 28 · first
Maine State AG+76d · this page

Pattern: first filing Jul 28 (ME), last Nov 19 (ME) — a 114-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.