McMenamins, Inc.
bd_40847924a834e0f4 · schema v1 · pii pii-v1
Full breach record for McMenamins, Inc. →McMenamins, Inc. notified the New Hampshire Attorney General of a ransomware attack discovered on December 12, 2021, with unauthorized access dating back to December 7, 2021. The incident affected approximately 40,504 individuals, including current and former employees and investors, exposing PII such as SSNs, health data, and financial account info. McMenamins contained the breach, engaged forensic investigators, notified the FBI, and provided credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 7, 2021
Begins
Dec 12, 2021
Discovered
Jan 18, 2022
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecontibd_d9892f7c34e2cea52021-12-21 · +28dVerified by operator
Regulatory filings (5) · sorted by filing gap
- Massachusetts State AGbd_c09f19d8ba46b5fa2022-01-18Verified by operator
- Maine State AGbd_feba65f7cb20750a2022-01-18Verified
- Washington State AGbd_48a7a67a3ff6841c2021-12-30 · +19dCandidate
- Oregon State AGbd_7f15c8a5259550dd2021-12-30 · +19dVerified
Show 1 more filing ↓Show fewer ↑up to 19d gap
- Indiana State AGbd_893688775c71c6d42021-12-30 · +19dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Dec 30 (WA), last Jan 18 (NH) — a 19-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.