Bose Ransomware Attack Exposed Employees’ Data Including Social Security Number, Company Discloses

Bose initiated incident response protocols to restore the impacted systems.

Advertisement
By Jasmin Jose | Updated: 26 May 2021 14:40 IST
Highlights
  • Bose offered 12 months of identity protection services to the employees
  • Bose said the threat actors interacted with a limited set of folders
  • Colonial Pipeline was also forced to halt its operations

Upon detecting the breach, Bose employed its technical team to contain the incident

Bose disclosed that the US-based company has been subject to a data breach following a ransomware attack in early March. Some of the employees' information was accessed by the attackers. The premium audio equipment maker filed a breach notification letter with New Hampshire's Office of the Attorney General around mid-May. Upon discovering the breach, the company initiated incident response protocols to restore the impacted systems. Bose also took a series of measures to protect itself from future attacks. Another ransomware attack on Colonial Pipeline had recently forced the shutdown of the largest oil pipeline in the eastern US earlier this month.

According to a breach notification letter from the company, Bose first discovered the attack on March 7. The company's data from internal administrative human resources files relating to six former New Hampshire employees were accessed and potentially exfiltrated. The accessed information included the employees' name, Social Security Number, and compensation-related information.

Upon detecting the breach, Bose employed its technical team to contain the incident. The company also worked with external forensics providers to investigate the attack. Bose said in the letter that the threat actors interacted with a limited set of folders and the systems have been restored.

Advertisement

Bose offered 12 months of identity protection services to the affected employees.

Advertisement

To defend itself from future cyberattacks, Bose detailed the following measures in its letter:

  • Enhanced malware/ ransomware protection on endpoints and servers to further enhance our protection against future malware/ ransomware attacks.
  • Performed detailed forensics analysis on impacted server to analyse the impact of the malware/ ransomware.
  • Blocked the malicious files used during the attack on endpoints to prevent further spread of the malware or data exfiltration attempt.
  • Enhanced monitoring and logging to identify any future actions by the threat actor or similar types of attacks.
  • Blocked newly identified malicious sites and IPs linked to this threat actor on external firewalls to prevent potential exfiltration.
  • Changed passwords for all end-users and privileged users.
  • Changed access keys for all service accounts.

The largest fuel network in the eastern US, Colonial Pipeline, was also forced to halt its operation earlier this month following a ransomware attack. The company paid $4.4 million (roughly Rs. 32.19 crores) in ransom to hackers following the attack.


It's Google I/O time this week on Orbital, the Gadgets 360 podcast, as we discuss Android 12, Wear OS, and more. Later (starting at 27:29), we jump over to Army of the Dead, Zack Snyder's Netflix zombie heist movie. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPad Air (2026) With M4 Chip Launched in India at This Price
  2. iPhone 17e Launched in India With MagSafe, 48-Megapixel Camera: See Price
  3. Nothing Phone 4a Price in India, RAM and Storage Options Leaked Online
  4. Poco X8 Lineup, Poco C85x 5G Appear on Flipkart Ahead of Launch
  5. Samsung Galaxy S27 Ultra May Come With This Major Camera Upgrade
  6. MediaTek to Demonstrate 6G, Wi-Fi 8 CPE, AI Glasses at MWC 2026
  1. Poco X8 Series, Poco C85x 5G Teased on Flipkart, Could Launch in India in March
  2. iPad Air (2026) Launched in India With M4 Chip, Up to 13-Inch Display: Price, Specifications
  3. iPhone 17e Launched in India With MagSafe, Ceramic Shield 2 and A19 Chip: Price, Specifications
  4. MWC 2026: Tecno Camon 50 Series Launched as Firm Unveils Modular Concept Phone, Lamborghini Collaboration
  5. Samsung Galaxy S26 Ultra's Successor Tipped to Feature 200-Megapixel ISOCELL HPA Sensor With LOFIC
  6. Moto Buds 2 Plus Launched With Dynamic ANC, Sound by Bose Alongside Moto Buds 2 at MWC 2026
  7. MediaTek Set to Demonstrate 6G, 5G-Advanced, Edge AI Innovations at ‘AI For Life’ Showcase at MWC 2026
  8. MWC 2026: Lenovo Unveils New Yoga, IdeaPad Series Laptop Models Alongside Legion Tab (2026), Idea Tab Pro Gen 2
  9. Bluepoint Games Reportedly Pitched a Bloodborne Remake, but Was Turned Down by FromSoftware
  10. Lenovo ThinkPad T-Series, X13 Detachable, ThinkTab X11 and ThinkBook 14 2-in-1 Launched at MWC 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.