On July 8, 2024, Stillwater Mining Company, a part of the Sibanye-Stillwater group, discovered a significant data breach that affected its information and communications technology systems. This breach was part of a cyber-attack that compromised systems within their global network.
An investigation revealed unauthorized activity on certain U.S. systems dating back to mid-June 2024. As a result, the personal information of 7,258 individuals in the United States was exposed, including sensitive data such as Social Security numbers, medical records, and financial account details.
The breach was disclosed to the Massachusetts Attorney General's office, affecting at least four individuals in Massachusetts and two in Maine. For more detailed information, you can view the disclosures on the Maine Attorney General's website and the Massachusetts Attorney General's website.
Upon discovering the breach, Stillwater Mining Company quickly took steps to contain and remediate the incident. They initiated their Incident Response plan and engaged external cybersecurity experts and forensic firms to assist in the investigation. The company has been closely monitoring their systems for any further activity and has implemented additional security measures, such as refining password policies and enhancing end-point detection and real-time monitoring capabilities.
As a precaution, they are offering affected individuals free identity and credit monitoring services through Experian.
If you have been affected by this data breach, it is crucial to take proactive steps to protect your personal information. Here are some recommended actions:
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.