Monarch
bd_b6df4d1b7711952d · schema v1 · pii pii-v1
Full breach record for Monarch →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Donutleaks on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Sep 1, 2022
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_0d05d83f025e0d072022-12-16 · +106dVerified
- Indiana State AGbd_d0bc38767e03616e2022-12-16 · +106dVerified
- Massachusetts State AGbd_ec9dcd6d8207a42d2022-12-20 · +110dVerified by operator
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Sep 1, last Dec 20 (MA) — a 110-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
donutleaks
According to ransomware.live, Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform.