DisclosureLens
MalwareRetail & ConsumerRetailRansomwareData EncryptedRansom DemandedIdentity (basic)Government IDFinancial accountMediumContained

KMG Prestige

bd_f23c18812ccad079 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 28, 2021

Filed

Feb 7, 2022

To disclose

10 weeks

Affected

3state residents only

Linked

6 filings

Confidence

66%
Full breach record for KMG Prestige

KMG Prestige, Inc. notified Montana residents of a ransomware incident discovered on November 28, 2021, impacting data likely accessed on November 27, 2021. Compromised data included names, driver's license numbers, SSNs, and health insurance info. The company engaged forensic experts and the FBI, restored systems, and offered 12 months of credit monitoring.

Incident timeline

undetected · 1 days
discovery → filing · 10 weeks / 71 days

Nov 27, 2021

Begins

Nov 28, 2021

Discovered

Feb 7, 2022

Filed

vs. sector median

+3 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 4 states

View merged incident ↗
Indiana State AGFeb 7 · first
Montana State AGFeb 7 · first · this page

Pattern: first filing Feb 7 (IN), last Feb 14 (MA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.