HackingNAICS CuData ExfiltratedEmployee Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICPIIMediumContained
SNAP-ON INCORPORATED
bd_75fcdb24d69d532b · schema v1 · pii pii-v1
Full breach record for SNAP-ON INCORPORATED →Snap-on, Inc. reported a data breach occurring between March 1 and March 3, 2022, involving unauthorized access to associate and franchisee data. The incident exposed names, Social Security Numbers, dates of birth, and employee identification numbers. Snap-on contained the breach, notified the FBI, and engaged forensic investigators. Affected individuals were offered 24 months of credit monitoring and fraud detection services through IDX.
California clockDiscovered Mar 3, 2022 → Notified Apr 7, 202235d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_a519fc8ef0091a27Leak Sitecontifiled 2022-04-10(3d gap)Verified by operator
Regulatory filings (4) · sorted by filing gap
- bd_513f6c7ab841506cMaine State AGfiled 2022-04-07Candidate
- bd_f5815b56cbb965e5Montana State AGfiled 2022-04-07Verified by operator
- bd_f2d77bd4c6ff9313Washington State AGfiled 2022-04-14(7d gap)Verified by operator
- bd_9938b1400eebc4f5Oregon State AGfiled 2022-04-20(13d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-552390
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 7, 2022
- Raw hash
- 22250f6f8cb8c9a00f59099fcf34eb2503247897254b9097a1e04fd6382b9295
Reporting entity
- Name
- SNAP-ON INCORPORATEDnorm: snap on
- Domain
- snap-on.com
Victim entity
- Name
- SNAP-ON INCORPORATEDnorm: snap on
- Domain
- snap-on.com
Incident
- Discovered
- Mar 3, 2022
- Materiality determined
- —
- Notification sent
- Apr 7, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 35d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 3, 2022→ Notified: Apr 7, 202235d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.