HackingRetail & ConsumerRetailCapture Stored DataData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPIIPHIPCIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICFINANCIALMediumContained
Murray's Cheese
bd_b7c6cefd9727bb32 · schema v1 · pii pii-v1
Full breach record for Murray's Cheese →Murray's Cheese LLC reported an external network breach occurring between February 15–21, 2026, discovered April 3, 2026. An unauthorized actor accessed and exfiltrated files containing employee health plan data including names, SSNs, dates of birth, health insurance enrollment info, and potentially driver's license numbers, passport numbers, financial account information, and medical records. Five Maine residents were affected. Epiq credit monitoring offered for one year.
Leak gap clock⏱ Leak >30d18 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 59 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_bca098857be8dd77Indiana State AGfiled 2026-04-21Verified
- bd_2883a9d7b008bc4eNew Hampshire State AGfiled 2026-05-27(36d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/9e77aec0-7382-4999-bf3c-75ace80cde5c.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2026
- Raw hash
- 166f3a9c64f9bc921aa28a8e5f9c48a804646303ec359122b8628a730e48dc53
Reporting entity
- Name
- Murray's Cheesenorm: murray s cheese
- Domain
- murrayscheese.com
- Industry
- Other Commercial
Victim entity
- Name
- Murray's Cheesenorm: murray s cheese
- Domain
- murrayscheese.com
- Industry
- Other Commercial
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Apr 3, 2026
- Materiality determined
- Apr 3, 2026
- Notification sent
- Apr 21, 2026
- Affected individuals
- 5
- Data types
- PIIPHIPCIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- Leak >30dME AG ≤30d · 18d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 3, 2026→ Filed with AG: Apr 21, 202618d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.