HackingPIIPCIIDENTITY_BASICLowActive
Barrett Firearms
bd_c09007a7674bf8fa · schema v1 · pii pii-v1
Full breach record for Barrett Firearms →Barrett-Jackson Holdings, LLC notified the Maryland Attorney General of a cyber incident occurring on or around November 25, 2024. The breach affected one Maryland resident, exposing their name and payment card data. The investigation is ongoing, and the company is providing 12 months of complimentary credit monitoring services to the affected individual.
Maryland clock✗ MD AG >90d15 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a437c3a939a38eacIndiana State AGfiled 2025-03-07Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376519.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 7, 2025
- Raw hash
- 8d9c0702486334b721926584178baf637df06a9787d73363f358d3133bf1468e
Reporting entity
- Name
- Cybersecurity & Data Privacynorm: cybersecurity data privacy
- Domain
- mullen.law
Victim entity
- Name
- Barrett Firearmsnorm: barrett firearms
- Domain
- barrett.net
Incident
- Discovered
- Nov 25, 2024
- Materiality determined
- —
- Notification sent
- Mar 7, 2025
- Affected individuals
- 1
- Data types
- PIIPCIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided notice to the Maryland Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.