K2 Sports, LLC
bd_f6aad3f7deb93872 · schema v1 · pii pii-v1
Full breach record for K2 Sports, LLC →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Blackbyte on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
About K2 Sports: Our mission is to create the most innovative tools for our consumers to provide the best experiences, push the sports, and strengthen the culture. K2 was born in 1962 as America’s ski company on Vashon Island in Washington State’s Puget Sound. Renamed in 2003 as K2 Sports and now based in Seattle, the company today is an international portfolio of world-renowned brands recognized as leaders in the innovation, marketing, and quality of our products and services. Driven by a passion for our sports and enthusiasts, we make alpine skis, snowboards, snowshoes, in-line skates, and Nordic ski equipment, apparel, and accessories.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jan 14, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_d8e9844c1b2f784a2023-07-17 · +184dCandidate
- New Hampshire State AGbd_f50a72d007d92a332023-07-21 · +188dVerified
Filing propagation · 3 filings · 2 states
View merged incident ↗Pattern: first filing Jan 14, last Jul 21 (NH) — a 188-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
blackbyte
According to ransomware.live, Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.