In April 2019, Cornerstone Building Brands, Inc. suffered a data breach where unauthorized actors gained access to two employees’ email accounts between April 1 and April 2, 2019. The incident was discovered and reported to the California Office of the Attorney General on September 11, 2019. While the exact nature of the compromised personal information was not publicly disclosed, the breach exposed sensitive data linked to the affected email accounts. The delay in detection (over five months) raises concerns about the company’s monitoring and response protocols. The breach primarily involved internal employee accounts, suggesting potential risks to corporate communications, proprietary data, or personally identifiable information (PII) of employees or associated parties. No evidence was provided regarding broader systemic exploitation, ransomware involvement, or direct financial fraud stemming from the incident. The company likely implemented remediation measures post-discovery, though specifics on containment or mitigation were not detailed in the report.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-150471
TPRM report: https://www.rankiteo.com/company/cornerstone-building-brands
"id": "cor031091825",
"linkid": "cornerstone-building-brands",
"type": "Breach",
"date": "4/2019",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Building Materials',
'location': 'California, USA',
'name': 'Cornerstone Building Brands, Inc.',
'type': 'Corporation'}],
'attack_vector': 'Unauthorized Email Access',
'data_breach': {'type_of_data_compromised': 'Personal Information '
'(unspecified)'},
'date_publicly_disclosed': '2019-09-11',
'description': 'The California Office of the Attorney General reported that '
'Cornerstone Building Brands, Inc. experienced a data breach '
'involving unauthorized access to two employees’ email '
'accounts between April 1 and April 2, 2019. The breach '
'potentially exposed personal information, although the '
'specific types of compromised data are not detailed.',
'impact': {'data_compromised': 'Personal Information (unspecified)',
'systems_affected': ['Two employees’ email accounts']},
'references': [{'source': 'California Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': ['California Office of '
'the Attorney '
'General']},
'title': 'Cornerstone Building Brands, Inc. Data Breach (2019)',
'type': 'Data Breach'}