DisclosureLens
MalwareTechnologyInformationRansomwareData ExfiltratedData EncryptedEmployee Data InvolvedGovernment IDIdentity (basic)MediumActive

DAVACO

bd_cfb65246deff18d4 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 11, 2021

Filed

Jul 19, 2021

To disclose

5 weeks

Affected

152state residents only

Linked

7 filings

Confidence

64%
Full breach record for DAVACO

Davaco, LP notified South Carolina residents on July 2, 2021, of a ransomware attack discovered on June 11, 2021. An unauthorized individual accessed the network, encrypted data, and exfiltrated employee personal information including names, SSNs, and driver's license numbers. Davaco hired forensic investigators, notified the FBI, and offered credit monitoring and identity theft protection services to affected employees.

Incident timeline

discovery → filing · 5 weeks / 38 days

Jun 11, 2021

Discovered

Jul 19, 2021

Filed

vs. sector median

13 wks faster

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 17d gap

Filing propagation · 7 filings · 7 states

View merged incident ↗
Indiana State AGJul 2 · first
Montana State AGJul 2 · first
South Carolina State AG+17d · this page

Pattern: first filing Jul 2 (IN), last Jul 19 (SC) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.