MarineMax, Inc.
ent_019dd17125cb29515b215a81b1425d1e
Disclosures
12
State AG · SEC 8-K · Leak Site · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
123,494
nationwide · State AG IN
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- MarineMax, Inc.
- Normalized
- marinemax— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900TIXTN8WY3FNN63
- SEC EDGAR CIK
- 0001057060
- Domain
- marinemax.com
Disclosure history (12)newest first
- Indiana State AGas victim2024-07-16
MarineMax, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-03-01 and was reported on 2024-07-16. 328 Indiana residents were affected. 123,494 individuals affected in total.
- Massachusetts State AGas victim2024-07-16
MarineMax, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-07-16. 3,139 Massachusetts residents were affected.
- South Carolina State AGas victim2024-07-16
MarineMax, Inc. reported a cybersecurity incident discovered on March 10, 2024, where an unauthorized third party accessed personal information. The company remediated the environment, engaged forensic experts, and notified law enforcement. Affected individuals are offered 24 months of credit monitoring and identity restoration services through Experian.
- New Hampshire State AGas victim2024-07-16
MarineMax, Inc. reported a cybersecurity incident to the New Hampshire Attorney General. Unauthorized access occurred between March 1 and March 10, 2024, discovered on March 10, 2024. The incident affected 448 New Hampshire residents, exposing personal information. MarineMax engaged forensic experts, notified the FBI, and offered credit monitoring via Experian to affected individuals.
- Vermont State AGas victim2024-07-16
MarineMax notified consumers of a data breach. The notice, filed with the Vermont Attorney General on July 16, 2024, offers 24 months of Experian IdentityWorks monitoring. Affected data likely includes names and government IDs. No specific count of affected individuals was provided in the filing.
- Maine State AGas victim2024-07-16
MarineMax, Inc. reported an external system breach (hacking) on March 10, 2024, affecting 123,494 individuals, including 153 Maine residents. The breach involved the acquisition of personal identifiers. MarineMax notified affected individuals on July 16, 2024, and provided 24 months of identity theft protection services through Experian.
- California State AGas victim2024-07-16
MarineMax, Inc. reported a data security breach to the California Attorney General. The incident occurred between March 1, 2024, and March 10, 2024. The notification letter indicates that affected individuals' information may include names, addresses, and Social Security numbers. MarineMax is offering 24 months of complimentary identity monitoring services through Experian IdentityWorks to affected individuals. The specific cause of the breach and the number of affected individuals are not detailed in the provided documents.
- Montana State AGas victim2024-07-16
MarineMax Inc issued a consumer notification letter to residents in multiple states, including Montana, regarding a cybersecurity incident. The letter provides instructions for enrolling in Experian IdentityWorks for 24 months, placing fraud alerts, and securing credit files. Specific details of the breach, such as the date of occurrence, discovery date, or number of affected individuals, are not present in this notification text.
- FEDERALSEC 8-Kas victim2024-04-01
MarineMax, Inc. (NYSE: HZO), a recreational boat and yacht retailer, disclosed on March 12, 2024 (amended April 1, 2024) that a cybercrime organization gained unauthorized access to portions of its information environment associated with its retail business. The threat actor exfiltrated limited customer and employee personally identifiable information. The company contained the incident, remediated the affected environment, notified law enforcement, and planned to notify affected parties and regulators.
- GLOBALLeak Siteas victim2024-03-20
MarineMax
- FEDERALSEC 8-Kas victim2024-03-12
On March 10, 2024, MarineMax, Inc. determined that a third party gained unauthorized access to portions of its information environment. The company initiated incident response and business continuity protocols, took containment measures (which caused some business disruption), engaged cybersecurity experts, and notified law enforcement. The company states it does not maintain sensitive data in the impacted environment. Investigation is ongoing; no material impact determined as of filing.
- GLOBALLeak Siteas victim2024-03-10
MarineMax