Clustered 5 filings across 5 jurisdictions · filed Dec 15, 2022. View entity profile → Other incidents for this victim →
incident inc_14b9eb7f7f21499f · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Government ID · Identity (basic)
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA ME MT NH WA
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Jul 29, 2022 → Sep 7, 2022
When the intrusion reportedly occurred, per the linked filings
Sep 7, 2022
Reported by CALIFORNIA AG, NEW HAMPSHIRE AG, WASHINGTON AG filings
Nov 18, 2022
Reported by MAINE AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Order Express, Inc. disclosed a data breach affecting California and other state residents. Unauthorized access occurred between July 29, 2022, and September 7, 2022. The company engaged third-party specialists to investigate and secure its network. Affected data included names combined with government identifiers. Order Express offered 12-24 months of complimentary credit monitoring and identity protection services to impacted individuals.
Order Express, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2022-12-15. The breach occurred from 7/29/2022 to 9/7/2022. 1 Montana residents were affected.
Affected (this filing): 1
Order Express, Inc., a financial services provider based in Chicago, IL, experienced an external system breach (hacking) on July 29, 2022. The incident compromised the names and driver's license numbers of 63,220 individuals, including 5 Maine residents. The breach was discovered on November 18, 2022. Order Express notified affected consumers in writing on December 15, 2022, and offered 12 months of credit monitoring services.
Affected (this filing): 63,220
Order Express, Inc. reported a ransomware attack discovered on September 7, 2022, involving unauthorized network access between July 29 and September 7, 2022. The incident impacted 3 New Hampshire residents, exposing names, driver's license numbers, and SSNs/TINs/ EINs. Order Express engaged third-party specialists, reset passwords, deployed EDR, and offered 12 months of credit monitoring.
Affected (this filing): 3
Order Express, Inc., a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-09-07 and filed notice on 2022-12-15. 1,168 Washington residents were affected. 99 days elapsed between awareness and notification. 40 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 1,168