MalwareRansomwareData EncryptedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTEMPLOYMENTHEALTH_BASICMediumContained
HANESBRANDS INC.
bd_f71ffedbeab73a05 · schema v1 · pii pii-v1
Full breach record for HANESBRANDS INC. →HanesBrands Inc. detected a ransomware incident on May 24, 2022, impacting internal IT systems. The incident has been contained. Affected data includes contact information, dates of birth, financial account information, government-issued IDs (SSN, driver's license, passport), and employment-related health information. The company engaged law enforcement, secured systems, and is offering two years of identity theft protection via Experian.
California clockDiscovered May 24, 2022 → Notified Aug 16, 202284d ✗ CA 60-day late12 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_9fb9627acb7eb000Montana State AGfiled 2022-08-16Candidate
- bd_f9d4220f22ced5eeMaine State AGfiled 2022-08-16Candidate
- bd_8c1ac18743a5161dOregon State AGfiled 2022-09-30(45d gap)Verified
- bd_416bfab051b743caWashington State AGfiled 2022-11-23(99d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 106d gap
- bd_1bff8c804887df1dNew Hampshire State AGfiled 2022-11-29(105d gap)Verified
- bd_77190cfcd636f76fCalifornia State AGfiled 2022-11-29(105d gap)Verified
- bd_c9aa4e72eaff47ccOregon State AGfiled 2022-11-29(105d gap)Verified
- bd_6bad099dc259b08fMaine State AGfiled 2022-11-30(106d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556309
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 16, 2022
- Raw hash
- 00ca22a64f1a63111fa6fa61a789e94f7d413e30c9578491c9f254014c7bf969
Reporting entity
- Name
- HANESBRANDS INC.norm: hanesbrands
Victim entity
- Name
- HANESBRANDS INC.norm: hanesbrands
Incident
- Discovered
- May 24, 2022
- Materiality determined
- —
- Notification sent
- Aug 16, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTEMPLOYMENTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to law enforcement
Compliance
- Time to disclose
- 12 weeks(84 days from discovery to filing)
- Compliance flags
- CA 60-day late · 84d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 24, 2022→ Notified: Aug 16, 202284d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.