HackingNAICS CuCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
SNAP-ON INCORPORATED
bd_513f6c7ab841506c · schema v1 · pii pii-v1
Full breach record for SNAP-ON INCORPORATED →Snap-on, Inc. reported an external system breach (hacking) occurring on March 3, 2022, discovered on March 7, 2022. The incident affected 41,052 individuals, including 320 Maine residents. Acquired data included names and driver's license numbers. Snap-on notified consumers on April 7, 2022, and provided 24 months of credit monitoring and identity theft protection services through IDX.
Maine clockDiscovered Mar 7, 2022 → Filed with AG Apr 7, 202231d ⏱ ME AG >30d4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_a519fc8ef0091a27Leak Sitecontifiled 2022-04-10(3d gap)Verified by operator
Regulatory filings (4) · sorted by filing gap
- bd_75fcdb24d69d532bCalifornia State AGfiled 2022-04-07Verified
- bd_f5815b56cbb965e5Montana State AGfiled 2022-04-07Verified by operator
- bd_f2d77bd4c6ff9313Washington State AGfiled 2022-04-14(7d gap)Verified by operator
- bd_9938b1400eebc4f5Oregon State AGfiled 2022-04-20(13d gap)Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/0af7be24-38b6-4a45-92fb-a41e3db04dc2.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 7, 2022
- Raw hash
- f299a4921350314b5ea7504eca90bc759f4d482a1057aec86fb0fd2595c62382
Reporting entity
- Name
- Morrison & Foerster LLPnorm: morrison foerster
Victim entity
- Name
- SNAP-ON INCORPORATEDnorm: snap on
- Domain
- snap-on.com
- Industry
- manufacturing
Incident
- Discovered
- Mar 7, 2022
- Materiality determined
- —
- Notification sent
- Apr 7, 2022
- Affected individuals
- 41,052
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed data breach notice with the Maine Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- ME AG >30d · 31d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 7, 2022→ Filed with AG: Apr 7, 202231d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.