MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTHighContained
McMenamins, Inc.
bd_40847924a834e0f4 · schema v1 · pii pii-v1
Full breach record for McMenamins, Inc. →McMenamins, Inc. notified the New Hampshire Attorney General of a ransomware attack discovered on December 12, 2021, with unauthorized access dating back to December 7, 2021. The incident affected approximately 40,504 individuals, including current and former employees and investors, exposing PII such as SSNs, health data, and financial account info. McMenamins contained the breach, engaged forensic investigators, notified the FBI, and provided credit monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_feba65f7cb20750aMaine State AGfiled 2022-01-18Verified
- bd_48a7a67a3ff6841cWashington State AGfiled 2021-12-30(19d gap)Candidate
- bd_7f15c8a5259550ddOregon State AGfiled 2021-12-30(19d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mcmenamins-20220118.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 18, 2022
- Raw hash
- 701b4a34b8d34f5ccc64fe09ee07d7335da7d590dbb920bee3ba086a0a37d374
Reporting entity
- Name
- McMenamins, Inc.norm: mcmenamins
Victim entity
- Name
- McMenamins, Inc.norm: mcmenamins
Incident
- Discovered
- Dec 12, 2021
- Materiality determined
- —
- Notification sent
- Dec 15, 2021
- Affected individuals
- 40,504
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Consumer Protection and Antitrust Bureau of the New Hampshire Attorney GeneralNotified the Attorney Generals of Oregon and Washington
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.