Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
Monro, Inc.
bd_597f39e11b1b7606 · schema v1 · pii pii-v1
Full breach record for Monro, Inc. →Monro, Inc. notified the Maryland AG of a security incident discovered on November 29, 2024, involving unauthorized access to an employee's email mailbox. The incident affected approximately 8,329 Maryland residents, exposing names, SSNs, addresses, DOBs, ID numbers, and employee health information (accident history). Monro engaged law enforcement, reset credentials, and offered 12 months of Experian IdentityWorks.
Maryland clock✗ MD AG >90d16 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3909ba1739d123c4Indiana State AGfiled 2025-03-21(1d gap)Verified
- bd_81844f5cb8cb5b78Delaware State AGfiled 2025-03-21(1d gap)Verified
- bd_f9efcb8fd813b56cCalifornia State AGfiled 2025-03-21(1d gap)Verified
- bd_688c27eeb1e682daNew Hampshire State AGfiled 2025-03-24(4d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 5d gap
- bd_098cf4205b448a91Vermont State AGfiled 2025-03-25(5d gap)Verified
- bd_eea3ee925e08d5fdMaine State AGfiled 2025-03-25(5d gap)Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376719.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 20, 2025
- Raw hash
- bd46c6c7c363937fe3494e2caeb56270eb31681d9dbb5bdf3271d8b458942706
Reporting entity
- Name
- Monro, Inc.norm: monro
Victim entity
- Name
- Monro, Inc.norm: monro
Incident
- Discovered
- Nov 29, 2024
- Materiality determined
- —
- Notification sent
- Mar 20, 2025
- Affected individuals
- 8,329
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified Maryland Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.