Bosley, Inc.
ent_ff88e5f742503b2513a5a04b
Disclosures
10
Leak Site · State AG · 10 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
100,855
nationwide · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Bosley, Inc.
- Normalized
- bosley— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 984500D8C599DS04EC50
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bosley.com
Disclosure history (10)newest first
- GLOBALLeak Siteas victim2021-09-09
- New Hampshire State AGas victim2021-01-27
Bosley, Inc., a hair restoration provider, experienced a ransomware incident on August 17, 2020. The malware encrypted data on certain systems. Forensic investigation later determined that an unauthorized party accessed systems containing personal information of over 100,000 individuals, including names, SSNs, financial account numbers, and driver's license numbers. 201 New Hampshire residents were affected. Bosley contained the incident, restored systems from backups, and offered one year of credit monitoring.
- Oregon State AGas victim2021-01-26
Bosley, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-01-26. The breach occurred during 8/17/2020 - 8/17/2020. The breach was discovered on 1/10/2021. 100,855 individuals were affected. Notice was sent on 1/26/2021.
- Indiana State AGas victim2021-01-26
Bosley, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-08-17 and was reported on 2021-01-26. 1,003 Indiana residents were affected. 100,855 individuals affected in total.
- Washington State AGas victim2021-01-26
Bosley, Inc., a hair restoration provider, notified the Washington AG of a ransomware incident discovered on August 17, 2020. The attack encrypted systems and led to the unauthorized access of personal information for 1,936 Washington residents, including names, SSNs, driver's license numbers, and financial account data. Bosley engaged forensic investigators, restored systems from backups, and began notifying affected individuals on January 25, 2021, offering one year of credit monitoring.
- Massachusetts State AGas victim2021-01-26
Bosley, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-01-26. 1,727 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2021-01-26
Bosley, Inc. experienced a ransomware incident on August 17, 2020, where malware encrypted data on certain computer systems. The company contained the malware and restored systems from backups. On September 24, 2020, it was determined that an unauthorized party had accessed systems containing customer personal information, including names, Social Security numbers, driver's license numbers, and financial account information. Bosley engaged a cybersecurity firm for investigation and offered one year of complimentary credit monitoring to affected individuals.
- Montana State AGas victim2021-01-26
Bosley, Inc. notified Montana residents of a ransomware incident on August 17, 2020, where malware encrypted data on certain computer systems. An unauthorized party gained access to systems containing customer and patient personal information, including names, SSNs, driver's license numbers, and financial account data. Bosley contained the incident, restored systems from backups, engaged a cybersecurity firm, and offered one year of credit monitoring via TransUnion.
- Maine State AGas victim2021-01-26
Bosley, Inc. reported an external system breach (hacking) occurring on August 17, 2020, discovered on January 10, 2020. The incident affected 100,855 individuals, including 158 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). Bosley provided written notification on January 16, 2021, and offered 12 months of credit monitoring and identity theft restoration services via TransUnion.
- Illinois State AGas victim2021-01-01
BOSLEY, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-033). The register records the breach as discovered on August 17, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.