811+
Bomco Inc., a precision metal components manufacturer for the aerospace industry, has begun notifying individuals about a data breach that occurred in June 2025. An unauthorized actor gained access to the company's network and may have exfiltrated files containing highly sensitive personally identifiable information (PII) and protected health information (PHI). The compromised data includes names, Social Security numbers, driver's licenses, financial account numbers, and health records. The company first detected suspicious activity on June 17, 2025, but the complex investigation took until April 20, 2026, to complete. Notification letters were sent to affected individuals starting on May 18, 2026, nearly eleven months after the initial intrusion.
The incident timeline reveals a significant delay between the breach, its discovery, and public notification:
The breach exposed a toxic combination of sensitive data, putting victims at high risk for identity theft and financial fraud. The affected data includes:
The provided information does not specify the initial access vector. However, such breaches typically occur through common methods like phishing attacks that lead to credential compromise, exploitation of unpatched vulnerabilities in external-facing systems, or brute-force attacks against remote access services. Once inside the network, the attacker was able to access and exfiltrate files over a three-day period. The long duration of the forensic investigation suggests that the compromised data was likely unstructured and spread across multiple systems, making it difficult to determine the exact scope of the breach.
T1567 - Exfiltration Over Web Service: The attacker likely copied files to an external location.T1552.001 - Credentials In Files: The breach exposed financial account numbers, which are often found in files.T1003 - OS Credential Dumping: A likely step for the attacker to escalate privileges and move laterally to access file servers.The primary impact is on the 811+ individuals whose data was stolen. The combination of SSNs, financial data, and health information is a worst-case scenario for data breach victims, enabling sophisticated forms of identity theft and fraud. For Bomco, the incident carries significant financial and reputational costs, including expenses for forensic services, credit monitoring for victims (24 months offered via IDX), and potential legal action. The lengthy delay between detection and notification may also draw scrutiny from state attorneys general and regulators.
No specific technical indicators of compromise (IPs, hashes, domains) were provided in the source articles.
Encrypting sensitive data at rest can prevent it from being usable by an attacker even if they manage to exfiltrate the files.
Applying the principle of least privilege to file shares ensures that a compromised account has access to a minimal amount of data, limiting the scope of a breach.
The period of unauthorized access to Bomco's network begins.
The period of unauthorized access to Bomco's network ends.
Bomco detects suspicious activity on its network.
A 10-month investigation into the breach concludes.
Bomco begins sending notification letters to affected individuals.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.