AVIENT CORPORATION
ent_019e231fffec7a8a9cb0b94b223b3b1f
Disclosures
4
SEC 10-K Item 1C · State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
35
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AVIENT CORPORATION
- Normalized
- avient— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- SM8L9RZYIB34LNTWO040
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- FEDERALSEC 10-K Item 1Cas victim2024-02-20
Avient Corporation's 10-K Item 1C cybersecurity disclosure describes the company's cybersecurity risk management program, governance structure, and oversight mechanisms. No specific cybersecurity incident is disclosed. The filing describes the CISO's role, the Audit Committee's oversight, the Avient Security and Privacy Council (ASPC), and the Cyber and Data Incident Response Team (CDIRT).
- 🍁Vermont State AGas victim2023-08-22
Avient Corporation notified Vermont AG of a cybersecurity incident discovered on April 9, 2023, involving unauthorized access to servers and workstations. The incident resulted in the exposure of personal information, including names and other PII. Avient engaged forensic investigators, restricted system access, reset passwords, implemented MFA, and offered two years of Kroll identity monitoring services to affected individuals.
- ⛰️New Hampshire State AGas victim2023-08-21
Avient Corporation reported a cyber security incident occurring on April 9, 2023, involving disruption to IT systems and workstations, consistent with a ransomware attack. The company determined on July 6, 2023, that personal information (PII) was stored on impacted servers. Avient engaged forensic firms, restricted system access, reset passwords, implemented MFA, and offered 24 months of Kroll identity monitoring to affected individuals.
- 🦞Maine State AGas victim2021-07-01
Avient Corporation reported a phishing incident that occurred between February 22, 2021, and March 1, 2021. The breach was discovered on May 27, 2021. The incident affected 35 Maine residents, compromising their names and Social Security numbers. The company provided written notification to affected individuals on July 1, 2021, and offered one year of credit monitoring and identity protection services through Experian.