MalwareRansomwareLockBit BlackLockBit 3.xData EncryptedData ExfiltratedEmployee Data InvolvedRansom DemandedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
KULICKE AND SOFFA INDUSTRIES, INC.
bd_be666efde9fec6fd · schema v1 · pii pii-v1
Full breach record for KULICKE AND SOFFA INDUSTRIES, INC. →Kulicke and Soffa Industries (K&S) experienced a ransomware attack on May 12, 2024, attributed to the 'LockBit Black' group. The threat actor encrypted files and potentially exfiltrated personal data of current/former employees and dependents, including names, identification numbers, bank account numbers, and routing numbers. K&S engaged forensic investigators and a cyber-negotiator. The incident has been contained. K&S is offering 12 months of identity theft resolution services via Experian.
California clockDiscovered May 12, 2024 → Notified Nov 21, 2024193d ✗ CA 60-day late28 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_8e5f97482b231358California State AGLockBit Blackfiled 2024-10-10(43d gap)Candidate
- bd_79afddd586c0be58Maine State AGfiled 2024-10-08(45d gap)Verified
- bd_bb0545fb8150a943Indiana State AGfiled 2024-10-08(45d gap)Verified
- bd_93092a8b694937b9Vermont State AGLockBit Blackfiled 2024-10-07(46d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-595272
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2024
- Raw hash
- d519a05a64c90fb4d71713fdc3328df5f8a63fdfd78e2a8331765e131eef4288
Reporting entity
- Name
- KULICKE AND SOFFA INDUSTRIES, INC.norm: kulicke and soffa
Victim entity
- Name
- KULICKE AND SOFFA INDUSTRIES, INC.norm: kulicke and soffa
Incident
- Discovered
- May 12, 2024
- Materiality determined
- —
- Notification sent
- Nov 21, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware· LockBit Black
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- LockBit BlackExternalFinancial
Compliance
- Time to disclose
- 28 weeks(194 days from discovery to filing)
- Compliance flags
- CA 60-day late · 193d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 12, 2024→ Notified: Nov 21, 2024193d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.