HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICPIILowContained
Maritz Holdings Inc.
bd_d6f87f82bc65a8eb · schema v1 · pii pii-v1
Full breach record for Maritz Holdings Inc. →Maritz Holdings Inc disclosed that an unauthorized third party exploited a previously unknown (zero-day) vulnerability in Oracle E-Business Suite to access and exfiltrate files from Maritz's environment between August 10 and August 13, 2025. The company became aware of the potential access in November 2025. Affected data includes names and other personal information. Maritz engaged third-party experts, notified law enforcement, and is offering 24 months of credit monitoring.
California clockDiscovered Nov 1, 2025 → Notified Apr 3, 2026153d ✗ CA 60-day late22 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_438cba26c14312fdLeak Sitecl0pfiled 2025-11-13(140d gap)Candidate
Regulatory filings (5) · sorted by filing gap
- bd_19465167e1507b6bTexas State AGfiled 2026-04-06(3d gap)Verified
- bd_4a5a64bea2308189California State AGfiled 2026-02-27(35d gap)Verified
- bd_511e8774e8b05d7cIndiana State AGfiled 2026-02-27(35d gap)Verified by operator
- bd_c572b0fed3fddb00Vermont State AGfiled 2026-02-27(35d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 35d gap
- bd_e6494ae402d92dcdMaine State AGfiled 2026-02-27(35d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621299
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2026
- Raw hash
- 079a9c255448770846158a261c65a5778261abcfde4e6116cb08ef25a190039e
Reporting entity
- Name
- Maritz Holdings Inc.norm: maritz holdings
- Domain
- maritz.com
Victim entity
- Name
- Maritz Holdings Inc.norm: maritz holdings
- Domain
- maritz.com
Incident
- Discovered
- Nov 1, 2025
- Materiality determined
- —
- Notification sent
- Apr 3, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 weeks(153 days from discovery to filing)
- Compliance flags
- CA 60-day late · 153dLeak >90dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 1, 2025→ Notified: Apr 3, 2026153d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Apr 3, 2026→ AG copy submitted: Apr 3, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.