McMenamins, Inc.
bd_48a7a67a3ff6841c · schema v1 · pii pii-v1
Full breach record for McMenamins, Inc. →McMenamins, Inc. reported a ransomware attack discovered on December 12, 2021, with unauthorized access dating back to December 7, 2021. The incident affected current and former employees and investors, exposing PII, SSNs, medical notes, and payroll data. Approximately 20,000 individuals were potentially affected, including 4,693 Washington residents. McMenamins engaged forensic investigators, notified the FBI, and provided credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 7, 2021
Begins
Dec 12, 2021
Discovered
Dec 30, 2021
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecontibd_d9892f7c34e2cea52021-12-21 · +9dVerified by operator
Regulatory filings (5) · sorted by filing gap
- Oregon State AGbd_7f15c8a5259550dd2021-12-30Verified
- Indiana State AGbd_893688775c71c6d42021-12-30Verified
- New Hampshire State AGbd_40847924a834e0f42022-01-18 · +19dVerified
- Massachusetts State AGbd_c09f19d8ba46b5fa2022-01-18 · +19dVerified by operator
Show 1 more filing ↓Show fewer ↑up to 19d gap
- Maine State AGbd_feba65f7cb20750a2022-01-18 · +19dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Dec 30 (OR), last Jan 18 (ME) — a 19-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.