Clustered 11 filings across 8 jurisdictions · filing window Jan 10, 2025 → Feb 11, 2025. View entity profile → Other incidents for this victim →
incident inc_78bff20073b54882 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA IN ME MT NH OR VT WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
11 filings across 8 jurisdictions · Jan 10, 2025 – Feb 11, 2025 · 3 milestones
Jul 18, 2024 → Dec 9, 2024
When the intrusion reportedly occurred, per the linked filings
Dec 9, 2024
Reported by WASHINGTON AG, NEW HAMPSHIRE AG, MAINE AG, CALIFORNIA AG, OREGON AG, VERMONT AG filings
Jan 4, 2025
Reported by MAINE AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Avery Products Corporation, a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2024-12-09 and filed notice on 2025-01-10. 1,724 Washington residents were affected. 32 days elapsed between awareness and notification. 144 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 1,724
Avery Products Corporation notified the NH AG of a ransomware attempt on its payment processing application between July 18 and Dec 9, 2024. Malicious software scraped payment card info from avery.com. 372 NH residents affected. Avery engaged forensic investigators, secured systems, and offered 12 months of credit monitoring.
Affected (this filing): 372
Avery Products Corporation reported an external system breach that occurred from July 18, 2024, to December 9, 2024. The breach was discovered on December 9, 2024, and affected 460 Maine residents. The company is offering 12 months of credit monitoring services through CyberScout to those affected.
Affected (this filing): 460
Avery Products Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2025-01-16. The breach occurred during 7/18/2024 - 12/9/2024. The breach was discovered on 12/9/2024. 61,100 individuals were affected. Notice was sent on 1/16/2025.
Affected (this filing): 61,100
Avery Products Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-18 and was reported on 2025-01-16. 1,195 Indiana residents were affected. 61,192 individuals affected in total.
Affected (this filing): 61,192
Avery Products Corporation experienced a ransomware attack affecting its website avery.com between July 18, 2024, and December 9, 2024. The company became aware of the incident on December 9, 2024. An unauthorized actor inserted malicious software to scrape credit card information, including CVV numbers and expiration dates, as well as names, addresses, and contact details. While initial evidence did not show exfiltration, subsequent reports of fraudulent charges suggest data may have been acquired. Avery engaged forensic experts, notified regulators, and is offering 12 months of credit monitoring to affected individuals.
Avery Products Corporation notified consumers of a ransomware attack discovered on December 9, 2024. Between July 18, 2024, and January 5, 2025, an unauthorized actor scraped credit card information, names, addresses, and CVVs from avery.com. The incident was reported to state regulators and AGs. Affected individuals are offered 12 months of credit monitoring.
Avery Products Corporation issued a supplemental notice to the NH AG regarding a ransomware attempt and malware incident affecting customer payment card data on avery.com. The incident occurred between July 18, 2024, and January 5, 2025. Malware embedded in the website cart scraped payment information. 400 New Hampshire residents were affected. Avery engaged forensic investigators and provided credit monitoring.
Affected (this filing): 400
Avery Products Corporation reported a data breach affecting 523 Maine residents. The breach, which was discovered on January 4, 2025, occurred between July 18, 2024, and January 5, 2025. The company described the incident as an external system breach or hacking. Affected individuals were notified on January 16, 2025, and offered 12 months of credit monitoring services through Cyber Scout.
Affected (this filing): 523
Avery Products Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2025-02-07. The breach occurred from 07/18/2024 to 01/05/2025. 308 Montana residents were affected.
Affected (this filing): 308
Avery Products Corporation experienced a ransomware attack discovered on December 9, 2024. An unauthorized actor inserted malicious software to scrape credit card information from avery.com between July 18, 2024, and January 5, 2025. Affected data includes names, addresses, email, phone, payment card numbers, CVV, expiration dates, and purchase amounts. The company engaged forensic experts, reported to regulators, and is offering 12 months of credit monitoring.