Carpenter Co.
ent_b6a72b0d4c64d69dcd3724ea
Disclosures
6
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
14,300
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Carpenter Co.
- Normalized
- carpenter— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300IM7JUVHOPE1O23
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- carpenter.com
Disclosure history (6)newest first
- Massachusetts State AGas victim2021-11-16
Carpenter Co. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-11-16. 30 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2021-09-11
Carpenter Co experienced a ransomware incident on March 18, 2021, impacting IT systems. The company did not pay the ransom. Forensic investigation confirmed on May 24, 2021, that threat actors accessed personal information of employees and contractors, including SSNs, DOBs, financial account details, and health information. The company contained the malware, locked out unauthorized users, and engaged forensic experts. Remediation included network monitoring and active directory hardening. Identity monitoring was provided via Kroll.
- Maine State AGas victim2021-09-11
Carpenter Co. experienced an external system breach on March 18, 2021, which was discovered the same day. The breach affected approximately 14,300 individuals, including 5 Maine residents, and compromised their names and Social Security numbers. In response, the company offered a 12-month membership to Kroll’s credit monitoring and identity theft restoration services.
- New Hampshire State AGas victim2021-07-29
Carpenter Co., a manufacturer of comfort cushioning products, experienced a ransomware incident on March 18, 2021, impacting its IT systems. The company did not pay the ransom. Forensic investigation confirmed on May 24, 2021, that a threat actor accessed personal information of employees and contractors, including names, dates of birth, and Social Security numbers. Five New Hampshire residents were affected. Carpenter contained the incident, removed malware, and is offering 12 months of credit monitoring to affected individuals.
- Indiana State AGas victim2021-07-28
Carpenter Co reported a data breach to the Indiana Attorney General. The breach occurred on 2021-03-18 and was reported on 2021-07-28. 970 Indiana residents were affected. 14,300 individuals affected in total.
- Montana State AGas victim2021-07-27
Carpenter Co. experienced a ransomware incident on March 18, 2021, impacting IT systems. The company did not pay the ransom. Forensic investigation confirmed unauthorized access to employees' and contractors' personal information. Response actions included law enforcement notification, system containment, and forensic investigation. Remediation included enhanced network monitoring and active directory hardening. Identity monitoring services were offered to affected individuals.