HackingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
JP Noonan Transportation Inc.
bd_b3cb8561752b5cc8 · schema v1 · pii pii-v1
Full breach record for JP Noonan Transportation Inc. →JP Noonan Transportation Inc. reported an external system breach (hacking) occurring in May 2021, discovered on September 15, 2021. The incident affected 7,421 individuals, including 336 Maine residents. Compromised data included names and financial account or credit/debit card numbers. The company provided written notification and offered 24 months of credit monitoring and identity restoration services.
Maine clockDiscovered Sep 15, 2021 → Filed with AG Oct 15, 202130d ✓ ME AG ≤30d4 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0b0ed264d76b6fb1Montana State AGfiled 2021-10-15Candidate
- bd_5aebb4c2c6be227eMaine State AGfiled 2021-10-15Verified by operator
- bd_61d94f6952a14cc8Maine State AGfiled 2021-11-10(26d gap)Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/bb77c09e-9cae-4aa8-98a3-76889fa99f8a.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 15, 2021
- Raw hash
- fb203e1e3a00ae86698fbb3ad50b26e92e0d5449547531e782244a930f2ef14d
Reporting entity
- Name
- JP Noonan Transportation Inc.norm: jp noonan transportation
- Domain
- jpnoonan.com
Victim entity
- Name
- JP Noonan Transportation Inc.norm: jp noonan transportation
- Domain
- jpnoonan.com
Incident
- Discovered
- Sep 15, 2021
- Materiality determined
- —
- Notification sent
- Jul 1, 2021
- Affected individuals
- 7,421
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 30d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Sep 15, 2021→ Filed with AG: Oct 15, 202130d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.