MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Bosley, Inc.
bd_e126f8548db710b8 · schema v1 · pii pii-v1
Full breach record for Bosley, Inc. →Bosley, Inc. experienced a ransomware incident on August 17, 2020, where malware encrypted data on certain computer systems. The company contained the malware and restored systems from backups. On September 24, 2020, it was determined that an unauthorized party had accessed systems containing customer personal information, including names, Social Security numbers, driver's license numbers, and financial account information. Bosley engaged a cybersecurity firm for investigation and offered one year of complimentary credit monitoring to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_3cdd2df174f8beb9Leak Sitepysafiled 2021-09-09(226d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_d120ef18cab32d85Washington State AGfiled 2021-01-26Verified
- bd_e640a3e9f964b9b2Montana State AGfiled 2021-01-26Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-537436
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 26, 2021
- Raw hash
- 4aec88f122b73b0cb829947b310fee2b43777433eab56c42abbd51c49fe45c6b
Reporting entity
- Name
- Bosley, Inc.norm: bosley
- Domain
- bosley.com
Victim entity
- Name
- Bosley, Inc.norm: bosley
- Domain
- bosley.com
Incident
- Discovered
- Aug 17, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
Compliance
- Time to disclose
- 23 weeks(162 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.