Arrow Truck Sales, Inc.
ent_f95ea35e865884c1bd345e66
Disclosures
9
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
18,087
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Arrow Truck Sales, Inc.
- Normalized
- arrow truck sales— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- Maine State AGas victim2021-08-04
Arrow Truck Sales, Inc. experienced an external system breach (hacking) on November 16, 2020, discovered on November 30, 2020. The incident compromised names and Social Security Numbers of 18,087 individuals, including 9 Maine residents. The company provided written notification starting January 8, 2021, and offered 24 months of credit monitoring through Kroll.
- New Hampshire State AGas victim2021-03-10
Arrow Truck Sales, Inc. filed a supplemental notice with the New Hampshire Attorney General on March 9, 2021, updating a prior January 2021 breach. The incident involved an unauthorized third party acquiring personal information, including names, Social Security numbers, and dates of birth, affecting 12 New Hampshire residents. The company provided 24 months of credit monitoring via Kroll and enhanced cybersecurity protections.
- California State AGas victim2021-02-26
Arrow Truck Sales, Inc. disclosed a cybersecurity incident where an unauthorized third party gained remote access to its network on or about November 30, 2020. The attacker acquired internal company information, including personal data of affected individuals, and posted it on a publicly accessible website. The company engaged outside cybersecurity experts, contacted law enforcement, and enhanced security protections. Affected individuals were offered two years of complimentary identity monitoring services through Kroll.
- Massachusetts State AGas victim2021-01-22
Arrow Truck Sales, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-01-22. 68 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2021-01-11
Arrow Truck Sales, Inc. notified the New Hampshire Attorney General on January 7, 2021, of a ransomware incident occurring on or about November 16, 2020. The attacker gained access using valid credentials, encrypted data, and exfiltrated customer names and Social Security numbers. Three New Hampshire residents were affected. Arrow engaged outside experts, notified law enforcement, and is offering 24 months of credit monitoring. The investigation was ongoing at the time of filing.
- Maine State AGas victim2021-01-11
Arrow Truck Sales, Inc. experienced an external system breach (hacking) on November 16, 2020, discovered on November 30, 2020. The incident compromised names and Social Security Numbers of 2,579 individuals, including one Maine resident. The company provided written notification on January 8, 2021, and offered 24 months of credit monitoring services through Kroll.
- Montana State AGas victim2021-01-08
Arrow Truck Sales, Inc. notified Montana residents of a cybersecurity incident occurring on or about November 30, 2020. An unauthorized third party gained remote access to the network, acquiring names and Social Security numbers. The company engaged law enforcement and cybersecurity experts, enhanced security protections, and provided two years of complimentary identity monitoring via Kroll.
- Indiana State AGas victim2021-01-08
Arrow Truck Sales, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-11-16 and was reported on 2021-01-08. 130 Indiana residents were affected. 18,087 individuals affected in total.
- Illinois State AGas victim2021-01-01
ARROW TRUCK SALES, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-097). The register records the breach as discovered on November 30, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.