Acuity Brands Reports Data Breach Impacting More than 37k Employees' Sensitive Information

Console and Associates, P.C.
Contact

On December 6, 2022, Acuity Brands reported a data breach with the Attorney General of Main after learning of a data security incident resulting in sensitive employee information being accessed and copied by an unauthorized party. According to Acuity, the breach resulted in the names, Social Security numbers, driver’s license numbers and financial account information belonging to employees being compromised. Recently, Acuity sent out data breach letters to all affected parties, informing them of the incident and what they can do to protect themselves from identity theft and other frauds.

When you accepted a position with Acuity Brands, you trusted that the company would keep your personal information secure. As a result, you didn’t hesitate to provide the company with your sensitive information. However, based on the company’s own statements, it now appears as though your information may be in the hands of an “unauthorized party,” such as a hacker or other criminal actor. However, as we’ve discussed previously, companies have a legal duty to protect employee information and, when they fail to implement reasonable protections against this type of breach, may be financially liable to victims.

What We Know About the Acuity Brands Data Breach

The available information regarding the Acuity Brands breach comes from the company’s filing with the Attorney General of Maine, as well as notice posted on the company’s website. According to these sources, on December 7, 2021, Acuity detected irregularities with the company’s IT system. In response, Acuity took steps to secure its network and then began working with a third-party data security firm in hopes of learning more about the incident and what, if any, consumer or employee data was compromised as a result.

Acuity’s investigation confirmed that an unauthorized party accessed certain computer systems on December 7, 2021, which lasted until December 8, 2021. The investigation also revealed that the unauthorized party copied a subset of files from the company’s network. However, Acuity was able to determine that the breach only affected employee data and that no consumer data was leaked.

Upon discovering that sensitive employee data was made available to an unauthorized party, Acuity Brands began to review the affected files to determine what information was compromised and which consumers were impacted. While the breached information varies depending on the individual, it may include your name, Social Security number, driver’s license number and financial account information.

On December 6, 2022, Acuity Brands sent out data breach letters to all individuals whose information was compromised as a result of the recent data security incident. According to the Attorney General of Maine, the Acuity Brands data breach affected over 37,000 current and former employees.

Established in 2001 and based in Atlanta, Georgia, Acuity Brands is a company that specializes in lighting and building management solutions. Acuity’s business is broken down into two groups, the lighting division and the intelligent spaces division. Acuity is the largest lighting manufacturer in the United States. Acuity Brands is publicly traded on the New York Stock Exchange under the ticker symbol “AYI.” Acuity Brands employs more than 13,000 people and generates approximately $3 billion in annual revenue.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Console and Associates, P.C.

Written by:

Console and Associates, P.C.
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Console and Associates, P.C. on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide