DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsData ExfiltratedTargetedIdentity (basic)Government IDFinancial accountHealth (basic)MediumContained

Astral Brands, Inc.

bd_ed54394177ee3ce9 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 22, 2023

Filed

Apr 25, 2023

To disclose

5 weeks

Affected

1state residents only

Linked

5 filings

Confidence

66%
Full breach record for Astral Brands, Inc.

Astral Brands, Inc. notified affected individuals of a cybersecurity incident where unauthorized access to its network resulted in the removal of files containing personal information between September 16-17, 2022. The data potentially included names, DOBs, SSNs, financial accounts, and medical info. Astral contained the threat, engaged external cybersecurity professionals, and offered 12 months of credit monitoring via TransUnion.

Incident timeline

undetected · 187 days
discovery → filing · 5 weeks / 34 days

Sep 16, 2022

Begins

Mar 22, 2023

Discovered

Apr 25, 2023

Filed

vs. sector median

3 wks faster

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Massachusetts State AGApr 25 · first
Indiana State AGApr 25 · first
Maine State AGApr 25 · first
Montana State AGApr 25 · first · this page

Pattern: first filing Apr 25 (MA), last May 1 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.