Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedPIIIDENTITY_BASICMediumContained
Monro, Inc.
bd_688c27eeb1e682da · schema v1 · pii pii-v1
Full breach record for Monro, Inc. →Monro, Inc. notified the New Hampshire Attorney General of a security incident discovered on November 29, 2024, involving unauthorized access to an employee's email mailbox. The incident likely resulted in the exposure of personal information for approximately 2,643 New Hampshire residents. Monro engaged law enforcement, reset credentials, and is offering 12 months of Experian IdentityWorks services to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_098cf4205b448a91Vermont State AGfiled 2025-03-25(1d gap)Verified
- bd_eea3ee925e08d5fdMaine State AGfiled 2025-03-25(1d gap)Candidate
- bd_3909ba1739d123c4Indiana State AGfiled 2025-03-21(3d gap)Verified
- bd_81844f5cb8cb5b78Delaware State AGfiled 2025-03-21(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 4d gap
- bd_f9efcb8fd813b56cCalifornia State AGfiled 2025-03-21(3d gap)Verified
- bd_597f39e11b1b7606Maryland State AGfiled 2025-03-20(4d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/monro-20250324.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 24, 2025
- Raw hash
- 1fae07ea1190c2cc6d376daf341ca7c3d372e3e4c53db2e4c4c756d83d2d78d9
Reporting entity
- Name
- Monro, Inc.norm: monro
Victim entity
- Name
- Monro, Inc.norm: monro
Incident
- Discovered
- Nov 29, 2024
- Materiality determined
- Jan 28, 2025
- Notification sent
- Mar 24, 2025
- Affected individuals
- 2,643
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 weeks(115 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.