MalwareRansomwareRansom DemandedRansom PaidData EncryptedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Sugar Bowl Corporation
bd_d1cf2054aa23b2fb · schema v1 · pii pii-v1
Full breach record for Sugar Bowl Corporation →Sugar Bowl Corporation experienced a ransomware attack on October 9, 2020, discovered on October 1, 2020. An unauthorized external actor accessed the network. Affected data may include names, addresses, and Social Security numbers of current and former employees. The company paid a ransom to obtain assurance that data was deleted and engaged forensic investigators. One year of Equifax ID Patrol is offered to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_72baf7b6337b9ef1Maine State AGfiled 2020-12-30Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197638
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 30, 2020
- Raw hash
- 4d5a960828014fc4ca0d7ef2dcfe0171c6b590d72362d8dd08b9e843aa31152f
Reporting entity
- Name
- Sugar Bowl Corporationnorm: sugar bowl
- Domain
- sugarsteel.com
Victim entity
- Name
- Sugar Bowl Corporationnorm: sugar bowl
- Domain
- sugarsteel.com
Incident
- Discovered
- Oct 1, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.