HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICAUTHENTICATIONMediumActive
Meyer Corporation
bd_e869c91ebee8530d · schema v1 · pii pii-v1
Full breach record for Meyer Corporation →Meyer Corporation, U.S. reported a cybersecurity incident occurring on or around October 25, 2021, involving unauthorized access to employee records. The breach potentially exposed personal information including names, addresses, SSNs, health data, and government IDs. Notifications were sent to employees in February 2022 offering two years of identity protection services. The investigation was conducted with third-party forensic experts.
California clockDiscovered Dec 1, 2021 → Notified Feb 15, 202276d ✗ CA 60-day late11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by conti about this victim predates this filing by 103 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0fafffc18815c227New Hampshire State AGfiled 2022-02-18Verified
- bd_1c7b98b318a93228Maine State AGfiled 2022-02-18Verified
- bd_2b872baf5334e545Montana State AGfiled 2022-02-15(3d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551092
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 18, 2022
- Raw hash
- 026e8a8e25eadead4670d7ba7d33839d508a05681ee98b5ad32a911a3e46017d
Reporting entity
- Name
- Meyer Corporationnorm: meyer
Victim entity
- Name
- Meyer Corporationnorm: meyer
Incident
- Discovered
- Dec 1, 2021
- Materiality determined
- —
- Notification sent
- Feb 15, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- CA 60-day late · 76dLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 1, 2021→ Notified: Feb 15, 202276d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.