SMC Corporation of America
ent_c1a6e3b153446515053f0cdd
Disclosures
9
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
6,566
nationwide · HHS OCR IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SMC Corporation of America
- Normalized
- smc corporation of america— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- smcusa.com
Disclosure history (9)newest first
- California State AGas victim2025-03-10
SMC Corporation of America and its subsidiary Advanced Pressure Technology (APTech) reported a data security breach affecting California residents. The incident, occurring on or about December 3, 2024, involved unauthorized access to systems containing personal information, including names and government-issued identifiers. SMC provided 24 months of credit monitoring and identity restoration services through Experian to affected individuals. The notification was submitted to the California Office of the Attorney General.
- New Hampshire State AGas victim2025-03-03
SMC Corporation of America notified the New Hampshire AG of a cybersecurity incident discovered on December 3, 2024. A foreign threat actor attempted to deploy ransomware and solicit payment, gaining unauthorized access for ~10 minutes. 64 NH residents (current/former employees) were affected. SMC restored systems from backups, negotiated for data suppression, and engaged experts/legal counsel. Notices were mailed Feb 3, 2025, offering credit monitoring.
- INDIANAHHS OCRas victim2025-02-27
SMC Corporation of America (Health Plan, IN) reported to HHS OCR on 2025-02-27 a Hacking/IT Incident affecting 6,566 individuals. Breached information was located on a Network Server. PHI involved included names, Social Security numbers, addresses, drivers' license numbers, dates of birth, diagnoses/conditions, and other treatment information. The CE notified HHS and affected individuals, provided complimentary credit monitoring, and implemented additional administrative, technical, and security safeguards.
- South Carolina State AGas victim2025-02-25
SMC Corporation of America notified employees of a cybersecurity incident discovered on December 8, 2024. A foreign threat actor gained unauthorized access to IT infrastructure, attempting to deploy ransomware and solicit payment. Personal information of U.S. and Canadian employees was exposed, including names, SSNs, bank details, and health data. SMC engaged cybersecurity experts and law enforcement, and is offering 24 months of credit monitoring.
- Massachusetts State AGas victim2025-02-24
SMC Corporation of America reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-02-24. 75 Massachusetts residents were affected.
- Maine State AGas victim2025-02-24
SMC Corporation of America reported a cybersecurity incident where a foreign threat actor gained unauthorized access to its IT infrastructure, attempting to deploy ransomware. The incident affected 6,566 current and former employees in the US and Canada, exposing personal information including SSNs, bank details, and medical data. SMC engaged forensic experts and law enforcement, and is offering 24 months of credit monitoring.
- Maryland State AGas victim2025-02-03
SMC Corporation of America notified Maryland AG of a cybersecurity incident discovered on Dec 8, 2024. A foreign threat actor gained unauthorized access to IT infrastructure, attempting to deploy ransomware and solicit a ransom. The incident exposed PII of current and former employees, including SSNs, bank info, and driver's licenses. 8 Maryland residents were identified as affected. SMC retained forensic experts, legal counsel, and provided 24 months of credit monitoring.
- Indiana State AGas victim2025-02-03
SMC Corporation of America reported a data breach to the Indiana Attorney General. The breach occurred on 2024-12-03 and was reported on 2025-02-03. 3,655 Indiana residents were affected. 6,566 individuals affected in total.
- Nebraska State AGas victim2025-02-03
SMC Corporation of America, a general business entity filed a data breach notification with the Nebraska Attorney General. The breach was discovered on 2025-01-10 according to the AG's register. The breach is dated 2024-12-03. Nebraska residents were notified on 2025-02-03.