HackingStolen CredentialsEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Monro, Inc.
bd_f9efcb8fd813b56c · schema v1 · pii pii-v1
Full breach record for Monro, Inc. →Monro, Inc. notified the California Attorney General of a security incident involving unauthorized access to an employee's electronic mailbox in late November 2024. The breach potentially exposed personal information including names, Social Security numbers, addresses, dates of birth, ID numbers, and certain health information (accident history) of employees. Monro changed passwords, modified email controls, and provided 12 months of Experian IdentityWorks to affected individuals.
California clockDiscovered Nov 21, 2024 → Notified Mar 21, 2025120d ✗ CA 60-day late17 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3909ba1739d123c4Indiana State AGfiled 2025-03-21Verified
- bd_81844f5cb8cb5b78Delaware State AGfiled 2025-03-21Verified
- bd_597f39e11b1b7606Maryland State AGfiled 2025-03-20(1d gap)Verified
- bd_688c27eeb1e682daNew Hampshire State AGfiled 2025-03-24(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 4d gap
- bd_098cf4205b448a91Vermont State AGfiled 2025-03-25(4d gap)Verified
- bd_eea3ee925e08d5fdMaine State AGfiled 2025-03-25(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-600257
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 21, 2025
- Raw hash
- e1328966f8c3b3de3c47754924d383fdaafd3d6c999422507d850c8e8f7f948a
Reporting entity
- Name
- Monro, Inc.norm: monro
Victim entity
- Name
- Monro, Inc.norm: monro
Incident
- Discovered
- Nov 21, 2024
- Materiality determined
- —
- Notification sent
- Mar 21, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 17 weeks(120 days from discovery to filing)
- Compliance flags
- CA 60-day late · 120d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 21, 2024→ Notified: Mar 21, 2025120d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.