HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
ACE HARDWARE CORPORATION
bd_cf8415c312a4875b · schema v1 · pii pii-v1
Full breach record for ACE HARDWARE CORPORATION →Ace Hardware Corporation notified New Hampshire residents of a data security incident discovered on October 29, 2023, involving unauthorized access to corporate systems between October 27-29, 2023. The incident potentially exposed personal information including names, addresses, and government IDs. Ace engaged third-party cybersecurity experts and law enforcement, implemented additional technical safeguards, and offered complimentary credit monitoring services to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_14fe6f10df22344fVermont State AGfiled 2024-04-01Verified
- bd_7c78088a02e5030cMontana State AGfiled 2024-04-01Candidate
- bd_81142c7264dd1e84Indiana State AGfiled 2024-04-01Verified
- bd_87a490160af062c6California State AGfiled 2024-04-01Verified
Show 2 more filings ↓Show fewer ↑
- bd_9b3e5f42ce97e604Maine State AGfiled 2024-04-01Verified by operator
- bd_be41d37097e367dfWashington State AGfiled 2024-04-01Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ace-hardware-20240401.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 1, 2024
- Raw hash
- fe284fa77f3c6a2f69f810788f1dcdc8e4c2e45cb4153d2f7419ba5981510a28
Reporting entity
- Name
- ACE HARDWARE CORPORATIONnorm: ace hardware
Victim entity
- Name
- ACE HARDWARE CORPORATIONnorm: ace hardware
Incident
- Discovered
- Oct 29, 2023
- Materiality determined
- —
- Notification sent
- Apr 1, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- worked closely with law enforcement who is conducting an active investigation into the unauthorized actor responsible for this incident
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 weeks(155 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.