MalwareRansomwareData ExfiltratedData EncryptedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumActive
DAVACO
bd_cfb65246deff18d4 · schema v1 · pii pii-v1
Full breach record for DAVACO →Davaco, LP notified South Carolina residents on July 2, 2021, of a ransomware attack discovered on June 11, 2021. An unauthorized individual accessed the network, encrypted data, and exfiltrated employee personal information including names, SSNs, and driver's license numbers. Davaco hired forensic investigators, notified the FBI, and offered credit monitoring and identity theft protection services to affected employees.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6400a333d4483ff5California State AGfiled 2021-07-19Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/Davaco.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 19, 2021
- Raw hash
- 86661b6c507ac74f95fcee92d58e58c6b3edef6ee63baa0665aaf4950ff714af
Reporting entity
- Name
- DAVACOnorm: davaco
- Domain
- davaco.com
Victim entity
- Name
- DAVACOnorm: davaco
- Domain
- davaco.com
Incident
- Discovered
- Jun 11, 2021
- Materiality determined
- —
- Notification sent
- Jul 2, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.