Clustered 7 filings across 7 jurisdictions · filed Jul 28, 2023. View entity profile → Other incidents for this victim →
incident inc_ec72dff429134e5c · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA ME MT NH OR VT WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Jun 14, 2023 → Jun 24, 2023
When the intrusion reportedly occurred, per the linked filings
Jun 24, 2023
Reported by WASHINGTON AG, VERMONT AG, CALIFORNIA AG filings
Jul 12, 2023
Reported by OREGON AG, MAINE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Cupertino Electric, Inc., a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-24 and filed notice on 2023-07-28. 884 Washington residents were affected. 34 days elapsed between awareness and notification. 10 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 884
Cupertino Electric, Inc. notified Vermont AG of a data breach affecting employee data (name, SSN, DOB, driver's license). Unauthorized access occurred June 14-24, 2023. CEI engaged forensic specialists, is reviewing security policies, and offering 24 months of credit monitoring to affected employees. Status is active.
Cupertino Electric, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-28. The breach occurred during 6/14/2023 - 6/24/2023. The breach was discovered on 7/12/2023. 24,684 individuals were affected. Notice was sent on 7/28/2023.
Affected (this filing): 24,684
Cupertino Electric, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-28. The breach occurred from 6/14/2023 to 6/24/2023. 80 Montana residents were affected.
Affected (this filing): 80
Cupertino Electric, Inc. notified 7 New Hampshire residents of a data security event on July 28, 2023. The company investigated, notified law enforcement, and provided two years of credit monitoring via TransUnion. Additional safeguards and employee training are being implemented.
Affected (this filing): 7
Cupertino Electric, Inc. reported an external system breach (hacking) occurring on June 14, 2023, discovered on July 12, 2023. The incident compromised names and Social Security Numbers of 24,684 individuals, including 3 Maine residents. The company notified affected individuals in writing on July 28, 2023, and provided 24 months of credit monitoring and identity theft protection services via TransUnion.
Affected (this filing): 24,684
Cupertino Electric, Inc. notified the California Attorney General of an unauthorized access incident affecting employee data. An unauthorized third party accessed systems between June 14 and June 24, 2023. The company became aware of suspicious activity on June 24, 2023. Affected data includes names, addresses, Social Security Numbers, driver's license numbers, and dates of birth for current and former employees. The company engaged third-party forensics, confirmed system security, and is offering 24 months of credit monitoring.