← Bath Fitter Distributing, Inc.

2024 Bath Fitter Distributing — ransomware; employee SSNs / gov IDs / financial data (notices 2025–2026)

2024 Unknown records affected Share on X

Data compromised

SSNs/SINs, government IDs, DOB, financial account numbers, HR/compensation and onboarding files (per company notice)

Technical writeup

Bath Fitter Distributing, Inc. confirmed a cybersecurity incident after a threat actor accessed its network around 4–5 December 2024 (ransomware reported in plaintiff/firm summaries). The company disabled VPN/remote access while rebuilding network segments and later completed investigation (reported completed about 7 March 2025). Massachusetts sample employee notices and state AG filings describe potentially exposed personnel-file data including Social Security numbers (U.S.) / social insurance numbers (Canada), passport and driver’s-license numbers, birth dates, financial account numbers (without PINs/passwords), health/safety and compensation fields, and onboarding materials. Interim notice went to current employees in December 2024 with credit monitoring; formal letters to current and former employees followed as the investigation finished, with Vermont AG disclosure activity reported around mid-July 2026. National headcount was not published in the sample notices reviewed (state filings cited small resident subsets such as ~49 NH / ~44 VT). Consumer-claim sites also frame customer exposure; primary company sample notice language centers on employee/personnel files.

Root cause

Ransomware / network intrusion (Dec 2024)

References