ACE Surgical Supply Co., Inc.
bd_ae9758955294443b · schema v1 · pii pii-v1
Full breach record for ACE Surgical Supply Co., Inc. →3 incidents on fileOn June 29, 2021, ACE Surgical Supply Co., Inc. discovered it was the victim of a ransomware cyberattack in which company files were accessed without authorization. The company secured its systems, contacted the FBI, and began an investigation. An initial notification was sent on July 28, 2021, to three affected Maine residents. In September 2021, the investigation identified an additional 25 affected customers who are Maine residents. The compromised customer information included names, contact information, and DEA and physician state license numbers. A second round of written notifications, including an offer for credit monitoring services, was sent to affected Maine residents on October 6, 2021. The investigation is ongoing, and there is no evidence that the compromised information has been made public or used for identity theft.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 29, 2021
Begins
Jun 29, 2021
Discovered
Oct 12, 2021
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- New Hampshire State AGbd_faf132798f4a305e2021-10-12Verified
- Montana State AGbd_0063ac3d9750d1d02021-10-06 · +6dVerified
- California State AGbd_4ca4fa02c48344602021-11-19 · +38dVerified
- Maine State AGbd_b29d69f2dc095b3b2021-11-19 · +38dVerified
Show 3 more filings ↓Show fewer ↑up to 76d gap
- Indiana State AGbd_b2f8ba19e8364d7e2021-08-25 · +48dVerified
- Maine State AGbd_2c4ef2fc29484f462021-07-28 · +76dCandidate
- New Hampshire State AGbd_f3cee4d3aaafd91f2021-07-28 · +76dVerified
Filing propagation · 8 filings · 5 states
View merged incident ↗Pattern: first filing Jul 28 (ME), last Nov 19 (ME) — a 114-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.