MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIALPIIMediumContained
A. Duda & Sons Inc.
bd_c6a3c369757bfe9c · schema v1 · pii pii-v1
Full breach record for A. Duda & Sons Inc. →A. Duda & Sons Inc. reported a data breach occurring between June 19 and July 10, 2022. Cybercriminals exploited security vulnerabilities to access IT systems, deployed ransomware to encrypt networks, and exfiltrated files containing PII, SSNs, payroll, and financial data. The company reported the incident to law enforcement, engaged outside consultants, and offered 24 months of credit monitoring to affected individuals.
California clockDiscovered Jul 9, 2022 → Notified Aug 3, 202225d ✓ CA 60-day OK25 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1a43af04930a557dOregon State AGfiled 2022-08-03Candidate
- bd_4f72abedbcfb0cbbMontana State AGfiled 2022-08-03Verified
- bd_6eb70b8dbaff7c05South Carolina State AGfiled 2022-08-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555895
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 3, 2022
- Raw hash
- f047edc901ca0125339c329d5b7a0abb736c56b3ade543c9fecacdbdb7d5b971
Reporting entity
- Name
- A. Duda & Sons Inc.norm: a duda sons
Victim entity
- Name
- A. Duda & Sons Inc.norm: a duda sons
Incident
- Discovered
- Jul 9, 2022
- Materiality determined
- —
- Notification sent
- Aug 3, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIALPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 25d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 9, 2022→ Notified: Aug 3, 202225d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.