MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Onix Group
bd_bf19a87cbef3951c · schema v1 · pii pii-v1
Full breach record for Onix Group →Onix Group, LLC reported a ransomware incident affecting internal systems between March 20 and March 27, 2023. Unauthorized access resulted in system corruption and file removal. Affected employee data included names, Social Security numbers, and financial account information. Onix engaged cybersecurity experts, secured systems, and offered one year of Experian IdentityWorks to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a367c281680ad7bbDelaware State AGfiled 2023-06-09(31d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/ELN-18053-Onix-Group-Ad-CM-1Y-Onix-Employee-Wave-3-r2prf.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2023
- Raw hash
- 3c53e4655cbab222cdf4892c88327e269b1e61911024ca9890c687d62a9d5a81
Reporting entity
- Name
- Onix Groupnorm: onix group
- Domain
- onixgroup.com
Victim entity
- Name
- Onix Groupnorm: onix group
- Domain
- onixgroup.com
Incident
- Discovered
- Mar 27, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 15 weeks(105 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.