Astral Brands, Inc.
bd_ed54394177ee3ce9 · schema v1 · pii pii-v1
Full breach record for Astral Brands, Inc. →Astral Brands, Inc. notified affected individuals of a cybersecurity incident where unauthorized access to its network resulted in the removal of files containing personal information between September 16-17, 2022. The data potentially included names, DOBs, SSNs, financial accounts, and medical info. Astral contained the threat, engaged external cybersecurity professionals, and offered 12 months of credit monitoring via TransUnion.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 16, 2022
Begins
Mar 22, 2023
Discovered
Apr 25, 2023
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_0aa52b0ed851b5792023-04-25Verified
- Indiana State AGbd_265288ccc0fa99c52023-04-25Verified
- Maine State AGbd_300ee5d95478ae952023-04-25Candidate
- New Hampshire State AGbd_1f7d7ddaa79fcd732023-05-01 · +6dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Apr 25 (MA), last May 1 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.