HackingVulnerability ExploitZero-DayData ExfiltratedPIIIDENTITY_BASICLowContained
HYPERTHERM, INC.
bd_e8719f6dfc09ffbd · schema v1 · pii pii-v1
Full breach record for HYPERTHERM, INC. →Hypertherm notified Vermont AG of a data breach involving an unauthorized actor exploiting a previously unknown vulnerability (zero-day) in Oracle E-Business Suite in August 2025. The incident resulted in the exfiltration of customer PII. Hypertherm patched the vulnerability and engaged Kroll to provide one year of complimentary identity monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday32 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 111 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_16da411c2f709b2eLeak Sitecl0pfiled 2025-11-21(111d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_596f4d56396a8274Indiana State AGfiled 2026-03-13Verified by operator
- bd_8e18d57ba2227437Maine State AGfiled 2026-03-13Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-13-hypertherm-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 13, 2026
- Raw hash
- 2510695234b5f01c277264a60a07d84b425100229b72d3cf788f5bda608d636a
Reporting entity
- Name
- HYPERTHERM, INC.norm: hypertherm
- Domain
- hypertherm.com
Victim entity
- Name
- HYPERTHERM, INC.norm: hypertherm
- Domain
- hypertherm.com
Incident
- Discovered
- Aug 1, 2025
- Materiality determined
- Mar 13, 2026
- Notification sent
- Mar 13, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 32 weeks(224 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.