HackingStolen CredentialsData ExfiltratedData PublishedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
RITCHIE BROS. AUCTIONEERS (AMERICA) INC.
bd_c382eb9185854c8d · schema v1 · pii pii-v1
Full breach record for RITCHIE BROS. AUCTIONEERS (AMERICA) INC. →Ritchie Bros. Auctioneers experienced a data breach between October 28 and November 15, 2021, involving unauthorized access to IT systems. The attacker misappropriated files containing personal information, including names and government identifiers, and made them available online. Ritchie Bros. terminated access, notified law enforcement, engaged external experts, and offered two years of complimentary credit monitoring and identity restoration services to affected individuals across multiple US states.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_10b3feb251797d27Maine State AGfiled 2022-03-11Verified
- bd_530dfff8d972625fMaine State AGfiled 2022-03-11Candidate
- bd_e0162dd86b6caf67Montana State AGfiled 2022-03-11Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551641
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 11, 2022
- Raw hash
- 386b297d09a50a8d04cfc0bb57ed4c9f571825615fb412767ce064e547491b3c
Reporting entity
- Name
- RITCHIE BROS. AUCTIONEERS (AMERICA) INC.norm: ritchie bros auctioneers america
Victim entity
- Name
- RITCHIE BROS. AUCTIONEERS (AMERICA) INC.norm: ritchie bros auctioneers america
Incident
- Discovered
- Nov 14, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the event to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(117 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.