HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Johnstone Supply
bd_ba193f11886e06b6 · schema v1 · pii pii-v1
Full breach record for Johnstone Supply →Wallace Supply LLC DBA Johnstone Supply notified Delaware residents of a data event involving unauthorized access to an employee email account between November 15 and 22, 2022. The incident potentially exposed names, SSNs, driver's license numbers, medical/health insurance info, and financial account data. Two Delaware residents were notified on February 24, 2023. The company secured the account, investigated, and offered 12 months of credit monitoring via Experian.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a003142b11ab39a2Delaware State AGfiled 2023-02-24Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/03/Johnstone-Supply-Notice-of-Data-Event-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 24, 2023
- Raw hash
- f1fd9e9792904e1f2f34a34bed2c358586bce4a307161405a41fa9cdf608139b
Reporting entity
- Name
- Johnstone Supplynorm: johnstone supply
- Domain
- johnstonesupply.com
Victim entity
- Name
- Johnstone Supplynorm: johnstone supply
- Domain
- johnstonesupply.com
Incident
- Discovered
- Nov 22, 2022
- Materiality determined
- —
- Notification sent
- Feb 24, 2023
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(94 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.