MalwareRansomwareData ExfiltratedData PublishedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICCREDENTIALSMediumActive
Hoya Optical Labs of America Inc.
bd_b4dc84b6b549745f · schema v1 · pii pii-v1
Full breach record for Hoya Optical Labs of America Inc. →Hoya Optical Labs of America, Inc. reported a ransomware incident to the New Hampshire Attorney General on June 11, 2021. The attack, discovered on April 5, 2021, involved file encryption and subsequent publication of stolen data by attackers. Approximately 4 New Hampshire residents were affected, with data including names, SSNs, financial account info, health data, and driver's licenses. Hoya engaged forensic investigators, notified law enforcement, and provided 2 years of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_b19a83a9b519a604Montana State AGfiled 2021-06-11Candidate
- bd_b3ab0c6e8ea4e75cMaine State AGfiled 2021-06-11Verified
- bd_ef4f85578523263bCalifornia State AGfiled 2021-06-11Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hoya-optical-20210611.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 11, 2021
- Raw hash
- eaf6a3d4b567af368ed27cbb358417d276b47ba7eb32a9c95915c5e38c6b365d
Reporting entity
- Name
- LOCKE LORD LLPnorm: locke lord
Victim entity
- Name
- Hoya Optical Labs of America Inc.norm: hoya optical labs of america
- Industry
- manufacturing
Incident
- Discovered
- Apr 5, 2021
- Materiality determined
- —
- Notification sent
- Jun 11, 2021
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified state agencies as required in jurisdictions where affected individuals reside
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.