DisclosureLens
MalwareHospitalityHospitalityRansomwareCapture Stored DataData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedTargetedAuthenticationEmploymentFinancial accountHealth (basic)Identity (basic)Government IDPHIHighContained

McMenamins, Inc.

bd_48a7a67a3ff6841c · schema v1 · pii pii-v1

Severity

High

Discovered

Dec 12, 2021

Filed

Dec 30, 2021

To disclose

18 days

Affected · nationwide

20,0004,693 in this filing

Linked

7 filings

Confidence

69%
Full breach record for McMenamins, Inc.

McMenamins, Inc. reported a ransomware attack discovered on December 12, 2021, with unauthorized access dating back to December 7, 2021. The incident affected current and former employees and investors, exposing PII, SSNs, medical notes, and payroll data. Approximately 20,000 individuals were potentially affected, including 4,693 Washington residents. McMenamins engaged forensic investigators, notified the FBI, and provided credit monitoring services.

Washington clock WA AG ≤30d18 days discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 5 days
discovery → filing · 18 days

Dec 7, 2021

Begins

Dec 12, 2021

Discovered

Dec 30, 2021

Filed

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 19d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Oregon State AGDec 30 · first
Indiana State AGDec 30 · first
Washington State AGDec 30 · first · this page

Pattern: first filing Dec 30 (OR), last Jan 18 (ME) — a 19-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.