MalwareRansomwareData ExfiltratedRansom DemandedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
MW Components
bd_e09ff3bc5f2bd8f2 · schema v1 · pii pii-v1
Full breach record for MW Components →MW Components disclosed a ransomware attack where an unauthorized third party accessed systems between March 1 and March 26, 2023. The company discovered the incident on March 26, 2023. Personal information, including basic identity data, may have been acquired. MW Components engaged forensic investigators, notified law enforcement, and enhanced security measures. Complimentary credit monitoring was offered to affected individuals.
California clockDiscovered Mar 26, 2023 → Notified Aug 28, 2023155d ✗ CA 60-day late22 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5cf56f6afff3cbc6Maine State AGfiled 2023-08-29Verified
- bd_5ee69a804aecb547New Hampshire State AGfiled 2023-08-30(1d gap)Candidate
- bd_961842e4dc0b2aadVermont State AGfiled 2023-08-28(1d gap)Verified
- bd_dce2bfbf462b0778New Hampshire State AGfiled 2023-08-01(28d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 32d gap
- bd_2f2ea2a07ebd3549California State AGfiled 2023-07-28(32d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572538
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2023
- Raw hash
- 2703047fa6a9dd2a16c2838f7a77518e51a1b47de48e54220d751ff4dde33e0d
Reporting entity
- Name
- MW Componentsnorm: mw components
- Domain
- mwcomponents.com
Victim entity
- Name
- MW Componentsnorm: mw components
- Domain
- mwcomponents.com
Incident
- Discovered
- Mar 26, 2023
- Materiality determined
- —
- Notification sent
- Aug 28, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 22 weeks(156 days from discovery to filing)
- Compliance flags
- CA 60-day late · 155dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 26, 2023→ Notified: Aug 28, 2023155d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.