Bath Fitter Distributing Inc.
ent_0a9e07b4a91333583cd005f4
Disclosures
9
Leak Site · State AG · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
3,451
nationwide · State AG ME
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Bath Fitter Distributing Inc.
- Normalized
- bath fitter distributing— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- GLOBALLeak Siteas victim2026-07-20
Employee data breach at a major manufacturing company.
- Vermont State AGas victim2026-07-16
Bath Fitter Distributing, Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-16. The reporting organization type is Other Commercial. 44 Vermont residents were affected. Categories of data breached: Social Security Numbers, Government ID Numbers, Financial Account Codes, Credit and Debit Account Info.
- Massachusetts State AGas victim2026-07-16
Bath Fitter (subsidiary of Bath Fitter Manufacturing Inc, owned by Bath Fitter Holdings Inc) disclosed a data breach involving unauthorized access by a criminal actor. Impacted data includes SSNs, DOBs, financial account numbers, health/safety info, and employment records. The company engaged a cybersecurity firm, implemented MFA, enhanced endpoint protection, and improved network segmentation. 24 months of credit monitoring via Epiq was offered. No specific count of affected individuals was disclosed.
- New Hampshire State AGas victim2026-07-15
Bath Fitter Distributing Inc. notified the NH Attorney General of a security incident on May 13, 2026, where a criminal actor gained unauthorized access to its systems and exfiltrated data. The breach affected 47 New Hampshire residents, who are current or former employees. Compromised data included social security numbers, financial account numbers, health and safety information, and employment records. The company isolated the network, engaged a cybersecurity firm, and implemented remediation measures including MFA and SOC monitoring. Credit monitoring is being offered to affected individuals.
- Massachusetts State AGas victim2025-04-24
Bath Fitter Distributing Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-04-24. 86 Massachusetts residents were affected.
- Nebraska State AGas victim2025-04-23
Bath Fitter Distributing Inc experienced a ransomware incident between December 4-5, 2024, discovered on December 5, 2024. A threat actor impersonated an IT technician to gain network access, deploy ransomware, encrypt files, and potentially exfiltrate data. The breach affected current and former employees, exposing SSNs, driver's licenses, passport numbers, financial account numbers, and health information. The company isolated the network, disabled remote access, built a new network, and offered two years of free credit monitoring via CyEx. Formal notification was sent on March 7, 2025.
- Maine State AGas victim2025-04-22
Bath Fitter Distributing Inc. reported a ransomware incident occurring Dec 4-5, 2024, discovered Dec 5, 2024. An external actor gained access via impersonation of IT support, deployed ransomware encrypting files, and potentially exfiltrated employee data including SSNs, driver's licenses, and financial info. 3,451 individuals affected (46 in Maine). Notifications sent April 23, 2025, offering 24 months credit monitoring.
- Indiana State AGas victim2025-04-18
Bath Fitter Distributing Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-12-04 and was reported on 2025-04-18. 96 Indiana residents were affected. 3,451 individuals affected in total.
- New Hampshire State AGas victim2025-04-15
Bath Fitter Distributing Inc. reported a ransomware attack occurring Dec 4-5, 2024. An external actor impersonated IT support to gain network access, encrypt files, and potentially exfiltrate data. The incident was discovered on Dec 5, 2024. Personal information of 49 New Hampshire current and former employees was impacted. The company isolated the network, disabled remote access, built a new network, and offered credit monitoring.