MalwareRansomwareVulnerability ExploitData ExfiltratedCustomer Data InvolvedRansom DemandedPCIFINANCIAL_ACCOUNTPIILowContained
Avery Products Corporation
bd_c0cb72b951b7a3ed · schema v1 · pii pii-v1
Full breach record for Avery Products Corporation →Avery Products Corporation notified the NH AG of a ransomware attempt on its payment processing application between July 18 and Dec 9, 2024. Malicious software scraped payment card info from avery.com. 372 NH residents affected. Avery engaged forensic investigators, secured systems, and offered 12 months of credit monitoring.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_dc0171a2cb3b6587Maine State AGfiled 2025-01-13Candidate
- bd_0133914d5cd708f9Oregon State AGfiled 2025-01-16(3d gap)Verified
- bd_9622529b26f17acfIndiana State AGfiled 2025-01-16(3d gap)Verified
- bd_9f8cfdfd51be813cCalifornia State AGfiled 2025-01-16(3d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 29d gap
- bd_3fc44f2276bcd5a0Washington State AGfiled 2025-01-10(3d gap)Verified
- bd_17d3515f645117e9Vermont State AGfiled 2025-01-29(16d gap)Verified
- bd_7c5c23e82caf557cNew Hampshire State AGfiled 2025-02-05(23d gap)Verified
- bd_b9944af515ad8d51Maine State AGfiled 2025-02-06(24d gap)Verified
- bd_a2e5641bcdbf5b89Montana State AGfiled 2025-02-07(25d gap)Verified
- bd_a6b982179a1d1f96California State AGfiled 2025-02-11(29d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/avery-products-20250113.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 13, 2025
- Raw hash
- e5ab4b4ebd2626411c1f6818521d8e5f03a5099990af12b126cad88399474a69
Reporting entity
- Name
- Avery Dennison Corpnorm: avery dennison
- Domain
- averydennison.com
Victim entity
- Name
- Avery Products Corporationnorm: avery products
- Domain
- avery.com
Incident
- Discovered
- Dec 9, 2024
- Materiality determined
- —
- Notification sent
- Jan 15, 2025
- Affected individuals
- 372
- Data types
- PCIFINANCIAL_ACCOUNTPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.