In January 2023, The Cannon Corp. Inc. suffered a targeted cyberattack that compromised sensitive personal data of current and former employees and their dependents in the U.S. Unauthorized parties accessed files containing names, dates of birth, contact details, Social Security numbers, driver’s license numbers, state ID numbers, and passport numbers. The breach led to a $537,500 class action settlement, with affected individuals eligible for up to $10,000 in reimbursements for financial losses (e.g., fraud, identity theft, legal fees) or a $40 pro rata cash payment, alongside two years of credit monitoring. The lawsuit alleged negligence in data protection, though Cannon denied liability. The breach exposed employees to identity theft, fraud, and long-term financial risks, with settlement funds covering administrative costs, legal fees, and claimant payouts. The incident underscored vulnerabilities in Cannon’s cybersecurity, resulting in reputational damage, financial penalties, and operational disruptions tied to litigation and remediation efforts.
Source: https://www.claimdepot.com/settlements/cannon-data-settlement
TPRM report: https://www.rankiteo.com/company/cannon-eng
"id": "can1194811100225",
"linkid": "cannon-eng",
"type": "Cyber Attack",
"date": "1/2023",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'Current and former employees '
'and their dependents (residing '
'in the U.S. at the time of the '
'breach)',
'location': 'United States',
'name': 'Cannon Corp. Inc.',
'type': 'Corporation'}],
'customer_advisories': 'Affected individuals instructed to file claims by '
'Nov. 25, 2025, for compensation (up to $10,000) or '
'credit monitoring services.',
'data_breach': {'data_exfiltration': 'Yes (files containing PII were '
'accessed)',
'file_types_exposed': ['Employee records'],
'personally_identifiable_information': ['Names',
'Dates of birth',
'Contact details',
'Social Security '
'numbers',
'Driver’s license '
'numbers',
'State identification '
'numbers',
'Passport numbers'],
'sensitivity_of_data': 'High (includes SSNs, driver’s license '
'numbers, passport numbers)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Sensitive employee and '
'dependent data']},
'date_detected': '2023-01',
'description': "A targeted cyberattack on Cannon Corp.'s computer systems in "
'January 2023 resulted in unauthorized access to files '
'containing sensitive employee and dependent information, '
'including names, dates of birth, contact details, Social '
'Security numbers, driver’s license numbers, state '
'identification numbers, and passport numbers. The breach led '
'to a class action lawsuit, settled for $537,500, with '
'affected individuals eligible for compensation up to $10,000 '
'or other benefits such as credit monitoring services.',
'impact': {'brand_reputation_impact': 'Class action lawsuit and settlement',
'data_compromised': ['Names',
'Dates of birth',
'Contact details',
'Social Security numbers',
'Driver’s license numbers',
'State identification numbers',
'Passport numbers'],
'financial_loss': '$537,500 (settlement fund)',
'identity_theft_risk': 'High (PII exposed, including SSNs, '
'driver’s license numbers, and passport '
'numbers)',
'legal_liabilities': "$537,500 settlement (including attorneys' "
'fees, administration costs, and claimant '
'payouts)',
'systems_affected': ["Cannon Corp.'s computer systems (files "
'containing employee data)']},
'initial_access_broker': {'high_value_targets': ['Employee PII data']},
'investigation_status': 'Settled (class action lawsuit resolved)',
'post_incident_analysis': {'root_causes': 'Alleged failure to adequately '
'protect sensitive employee data '
'(per class action lawsuit).'},
'references': [{'source': 'Class Action Settlement Notice'}],
'regulatory_compliance': {'legal_actions': 'Class action lawsuit settled for '
'$537,500'},
'response': {'communication_strategy': 'Notification letters sent to affected '
'individuals; class action settlement '
'process established (online/mail '
'claims, credit monitoring, and cash '
'payouts).'},
'stakeholder_advisories': 'Notification letters sent to affected employees '
'and dependents; settlement claims process '
'established (online/mail).',
'title': 'Cannon Corp. Data Breach (January 2023)',
'type': 'Data Breach'}