Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPIIMediumContained
Monro, Inc.
bd_098cf4205b448a91 · schema v1 · pii pii-v1
Full breach record for Monro, Inc. →Monro, Inc. disclosed a security incident in late 2024 involving unauthorized access to an employee's email mailbox. The attacker accessed personal information including names, Social Security numbers, addresses, dates of birth, and some employee health data. Monro notified affected individuals in multiple states, including Vermont and Rhode Island, and offered 12 months of credit monitoring via Experian IdentityWorks.
Vermont clock✗ VT AG >45 bday21 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_eea3ee925e08d5fdMaine State AGfiled 2025-03-25Candidate
- bd_688c27eeb1e682daNew Hampshire State AGfiled 2025-03-24(1d gap)Verified
- bd_3909ba1739d123c4Indiana State AGfiled 2025-03-21(4d gap)Verified
- bd_81844f5cb8cb5b78Delaware State AGfiled 2025-03-21(4d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 5d gap
- bd_f9efcb8fd813b56cCalifornia State AGfiled 2025-03-21(4d gap)Verified
- bd_597f39e11b1b7606Maryland State AGfiled 2025-03-20(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-25-monro-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2025
- Raw hash
- 9cd71a5dc9cab32044bb7c80a1a39ab86641d83ca8814f24442eec7a4c4aa9cd
Reporting entity
- Name
- Monro, Inc.norm: monro
Victim entity
- Name
- Monro, Inc.norm: monro
Incident
- Discovered
- Nov 1, 2024
- Materiality determined
- Mar 25, 2025
- Notification sent
- Mar 21, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 weeks(144 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.