DisclosureLens
HackingInformationCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

Cocoon, Inc.

bd_8de020024d6a87a8 · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 27, 2024

Filed

Apr 16, 2024

To disclose

20 days

Affected · nationwide

501 in this filing

Linked

3 filings

Confidence

50%
Full breach record for Cocoon, Inc.3 incidents on file

Cocoon Inc. reported an external system breach (hacking) that occurred on March 3, 2024, and was discovered on March 27, 2024. The breach affected one Maine resident, compromising their name in combination with financial account numbers or credit/debit card numbers. The company provided written notification to the affected individual on April 11, 2024, and offered one year of credit monitoring and identity theft protection services through IDX.

Maine clockDiscovered Mar 27, 2024Filed with AG Apr 16, 202420d ME AG ≤30d20 days discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 24 days
discovery → filing · 20 days

Mar 3, 2024

Begins

Mar 27, 2024

Discovered

Apr 16, 2024

Filed

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
New Hampshire State AGApr 16 · first
Maine State AGApr 16 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.