Central National Gottesman
Incident posture
Linked entities
- Victim
- Central National Gottesman
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A ransomware attack claimed by the group Payouts King exposed a broad range of sensitive personal data at Central National Gottesman, including Social Security numbers, driver's license and government ID numbers, financial and payment card information, medical and health insurance details, dates of birth, addresses, and contact information. Notification letters were sent to affected individuals after a significant delay, prompting two former employees to file suit alleging inadequate data protection. The breach heightens long-term risks of identity theft, financial fraud, and medical identity misuse for those impacted.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On or about March 2, 2026, Central National Gottesman, a Purchase, New York-based global distributor and marketer of paper, packaging, wood, tissue, and metal products, experienced a cyberattack claimed by a ransomware group identified as Payouts King. The incident, which became publicly known through subsequent lawsuits and breach notifications, marked the beginning of a roughly five-month interval between the attack itself and the company's formal communication with affected individuals. During that window, the exposed data sat within the reach of the threat actors, and the company's internal response was already underway or under preparation. The attack was not described in technical detail in the available reporting, which frames the event primarily through the lens of the legal investigation and the data-protection failures alleged by former employees, but its character as a ransomware incident is the central fact driving every subsequent disclosure and legal filing.
The first public legal response to the attack came in April 2026, when two former employees of Central National Gottesman filed suit against the company. Their complaint alleged that the organization had failed to adequately protect sensitive personal information and had delayed the notification of affected parties. The fact that the initial plaintiffs were former employees suggests that the dataset held by Central National Gottesman and compromised in the attack included records belonging not only to current workers but also to those whose employment had ended prior to the breach. The legal action also signaled early that the company's timeline and disclosure practices would be a central focus of the dispute, with plaintiffs pointing to the multi-month gap between the March intrusion and the eventual notification campaign as a critical harm in itself.
Central National Gottesman began notifying affected individuals on August 28, 2026, more than five months after the underlying attack. According to the breach notifications referenced in the available reporting, the exposed data potentially includes Social Security numbers, driver's license and government-issued identification numbers, financial information such as account and payment card numbers, medical and health insurance information, dates of birth, addresses, and contact details. The combination of these categories represents an unusually broad set of sensitive identifiers, increasing the likelihood that affected individuals could face downstream identity theft, financial fraud, and medical-record-related misuse. The breadth of the exposed fields is itself a material dimension of the incident, because each category carries distinct misuse potential and collectively they can be cross-referenced to assemble comprehensive profiles of the victims.
Following the start of the notification process, the law firm Edelson Lechtzin LLP announced an investigation into potential data privacy claims arising from the breach and began offering free, confidential case evaluations to individuals who received a breach notification from Central National Gottesman. The firm, a national class action firm with offices in Pennsylvania and California, identified Marc Edelson, Esq., as the contact attorney and provided a Newtown, Pennsylvania address along with a toll-free phone number and an email address for affected individuals to request consultations. The investigation is framed around the question of whether affected parties may be entitled to compensation for the exposure of their sensitive identifiers and the company's handling of the incident before, during, and after the attack. The announcement positioned the breach notification letter as the primary confirmation that a particular individual's information was involved, reinforcing the link between the company's notification effort and the legal process that followed.
As of the early September 2026 reporting, the public record describes the threat actor as the ransomware group Payouts King, the attack vector as ransomware, the date of the underlying intrusion as on or about March 2, 2026, the first lawsuits as filed in April 2026 by two former employees, and the start of consumer notifications as August 28, 2026. The available material does not specify the precise technical means by which the attackers gained access, the number of individuals affected, whether a ransom was paid, whether data was confirmed exfiltrated in addition to any encryption effects, or the duration of any operational disruption to Central National Gottesman's business. Reporting on the company itself focuses on its headquarters location in Purchase, New York, and its role as a global distributor of paper, packaging, wood, tissue, and metal products, with no public statements from the company regarding the incident appearing in the available source.
Sources
Sources available to members: 1 source.