MalwareRansomwareData EncryptedData ExfiltratedRansom DemandedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMedium
The North Highland Holding Company LLC
bd_f6fd1512ab6ececb · schema v1 · pii pii-v1
Full breach record for The North Highland Holding Company LLC →The North Highland Company, LLC experienced a ransomware incident starting on May 26, 2022, and discovered on June 28, 2022. The breach compromised the names and financial account or credit/debit card numbers (with access codes) of 10,623 individuals. The company began notifying affected individuals on July 7, 2022, and offered 24 months of identity theft protection services.
Maine clockDiscovered Jun 28, 2022 → Filed with AG Jul 28, 202230d ✓ ME AG ≤30d4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_52c6629a73a1db9dOregon State AGfiled 2022-07-29(1d gap)Verified
- bd_4a5a5be8d6ceb777Montana State AGfiled 2022-09-23(57d gap)Verified
- bd_43b6cf6e213c6816California State AGfiled 2022-09-26(60d gap)Verified
- bd_b03ec36e53e8b9baMaine State AGfiled 2022-09-26(60d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 60d gap
- bd_cd7f068cb537a689Oregon State AGfiled 2022-09-26(60d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/dcdea529-1e9f-4628-8606-7265bc1fec40.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2022
- Raw hash
- 50e93295c60b004e41b57a65bed987e699a6d41be17f32051c150922bd085d0a
Reporting entity
- Name
- The North Highland Holding Company LLCnorm: the north highland
Victim entity
- Name
- The North Highland Holding Company LLCnorm: the north highland
Incident
- Discovered
- Jun 28, 2022
- Materiality determined
- —
- Notification sent
- Jul 7, 2022
- Affected individuals
- 10,623
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 28, 2022→ Filed with AG: Jul 28, 202230d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.