HackingRetail & ConsumerRetailCapture App DataAbuse Of FunctionalityCustomer Data InvolvedData ExfiltratedPIIPCILowContained
Mann Lake Acquisition, Inc.
bd_e24241ed9076b230 · schema v1 · pii pii-v1
Full breach record for Mann Lake Acquisition, Inc. →Mann Lake Acquisition, Inc. reported an external hacking incident in which an unknown actor could have accessed payment card information from customers who made purchases on mannlakeltd.com or strombergschickens.com between March 14–27, 2025. The activity was discovered on April 11, 2025 following investigation. Name and payment card information were potentially accessed. 82 Maine residents were notified on May 9, 2025. Twelve months of credit monitoring via TransUnion (Cyberscout) was offered.
Maine clockDiscovered Apr 11, 2025 → Filed with AG May 9, 202528d ✓ ME AG ≤30d28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_05fa25ea53c7a0e4New Hampshire State AGfiled 2025-05-09Verified
- bd_433f7ed32839b51eMontana State AGfiled 2025-05-09Candidate
- bd_88f4984a8dace13dVermont State AGfiled 2025-05-09Verified
- bd_bba84467830d9098Indiana State AGfiled 2025-05-09Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/6558a5c0-3a99-45f9-bfd6-c37b3ab913f4.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 9, 2025
- Raw hash
- 80b9ebc1c11c3fa90adcbf97ab6aec84c9467c8fe64e365a98e3d7312e8dde18
Reporting entity
- Name
- Mann Lake Acquisition, Inc.norm: mann lake acquisition
- Domain
- mannlakeltd.com
- Industry
- Other Commercial
Victim entity
- Name
- Mann Lake Acquisition, Inc.norm: mann lake acquisition
- Domain
- mannlakeltd.com
- Industry
- Other Commercial
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Apr 11, 2025
- Materiality determined
- —
- Notification sent
- May 9, 2025
- Affected individuals
- 82
- Data types
- PIIPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1056.003 Web Portal CaptureT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maine Attorney GeneralNotified three major credit reporting agencies: Equifax, Experian, TransUnion
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 28d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 11, 2025→ Filed with AG: May 9, 202528d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.