Hy LaBonne & Sons, Inc.
ent_6c2433df59bf3e7009af8cec
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,434
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Hy LaBonne & Sons, Inc.
- Normalized
- hy labonne sons— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- New Hampshire State AGas victim2026-05-05
Hy LaBonne & Sons, Inc. (dba LaBonne's Markets) notified the NH Attorney General of a cyberattack on October 20, 2025, where unauthorized access led to the download of files containing names, SSNs, and medical information for approximately 16 NH residents. The company engaged forensic specialists, notified law enforcement, and is offering 24 months of credit monitoring.
- Indiana State AGas victim2026-05-05
Hy LaBonne & Sons Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-10-20 and was reported on 2026-05-05. 3 Indiana residents were affected. 3,434 individuals affected in total.
- Massachusetts State AGas victim2026-05-05
Hy LaBonne & Sons, Inc. notified Massachusetts residents of a cybersecurity incident involving potential unauthorized access to personal information. The company offered 24 months of credit monitoring and identity theft protection via Experian. The investigation is ongoing, and the company reported the event to law enforcement.
- Vermont State AGas victim2026-05-05
Hy LaBonne & Sons, Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-05-05. The reporting organization type is Other Commercial. 10 Vermont residents were affected. Categories of data breached: Social Security Numbers.
- Maine State AGas victim2026-05-05
Hy LaBonne & Sons, Inc. reported an external system breach (hacking) on October 20, 2025, discovered on March 16, 2026. The incident affected 18 Maine residents, involving unauthorized access to files containing names and other personal identifiers. The company engaged cybersecurity specialists, notified law enforcement, and provided 24 months of credit monitoring via Experian.