DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsEmployee Data InvolvedIdentity (basic)Government IDFinancial accountAuthenticationMediumContained

McLane Company, Inc.

bd_90d2bb2c7d05aa7d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 20, 2024

Filed

Nov 13, 2025

To disclose

Affected

9state residents only

Confidence

66%
Full breach record for McLane Company, Inc.3 incidents on file

McLane Company, Inc. notified the Maryland Attorney General of a data event involving its eServe payroll platform. An unauthorized actor exploited a vulnerability to access accounts between October 12 and November 22, 2024, modifying direct deposit info. Nine Maryland residents were affected, with data including names, SSNs, DOBs, and bank account numbers. McLane engaged forensic specialists, provided 12 months of credit monitoring via TransUnion, and implemented additional security measures.

Incident timeline

undetected · 39 days

Oct 12, 2024

Begins

Nov 20, 2024

Discovered

Nov 13, 2025

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed9 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.