Clustered 7 filings across 7 jurisdictions · filing window Mar 20, 2025 → Mar 25, 2025. View entity profile → Other incidents for this victim →
incident inc_27c59f0be2734340 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA DE IN MD ME NH VT
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Nov 1, 2024 – Nov 29, 2024
Earliest reported discovery Nov 1, 2024
Nov 1, 2024
Reported by DELAWARE AG, VERMONT AG filings
Nov 21, 2024
Reported by CALIFORNIA AG filing
Nov 29, 2024
Reported by MARYLAND AG, NEW HAMPSHIRE AG, MAINE AG filings
Nov 29, 2024
When the intrusion reportedly occurred, per the linked filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Monro, Inc. notified the Maryland AG of a security incident discovered on November 29, 2024, involving unauthorized access to an employee's email mailbox. The incident affected approximately 8,329 Maryland residents, exposing names, SSNs, addresses, DOBs, ID numbers, and employee health information (accident history). Monro engaged law enforcement, reset credentials, and offered 12 months of Experian IdentityWorks.
Affected (this filing): 8,329
Monro Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-11-21 and was reported on 2025-03-21. 4,406 Indiana residents were affected. 112,458 individuals affected in total.
Affected (this filing): 112,458
Monro, Inc. notified affected individuals in multiple states (including Delaware and Rhode Island) of a security incident in late 2024 involving unauthorized access to an employee's email account. The breach exposed names, Social Security numbers, dates of birth, and employee health/accident history. Approximately 975 Rhode Island residents were specifically identified. Monro offered 12 months of credit monitoring via Experian.
Affected (this filing): 975
Monro, Inc. notified the California Attorney General of a security incident involving unauthorized access to an employee's electronic mailbox in late November 2024. The breach potentially exposed personal information including names, Social Security numbers, addresses, dates of birth, ID numbers, and certain health information (accident history) of employees. Monro changed passwords, modified email controls, and provided 12 months of Experian IdentityWorks to affected individuals.
Monro, Inc. notified the New Hampshire Attorney General of a security incident discovered on November 29, 2024, involving unauthorized access to an employee's email mailbox. The incident likely resulted in the exposure of personal information for approximately 2,643 New Hampshire residents. Monro engaged law enforcement, reset credentials, and is offering 12 months of Experian IdentityWorks services to affected individuals.
Affected (this filing): 2,643
Monro, Inc. disclosed a security incident in late 2024 involving unauthorized access to an employee's email mailbox. The attacker accessed personal information including names, Social Security numbers, addresses, dates of birth, and some employee health data. Monro notified affected individuals in multiple states, including Vermont and Rhode Island, and offered 12 months of credit monitoring via Experian IdentityWorks.
Monro, Inc. reported a data breach to the Maine Attorney General, stating that an external system breach (hacking) occurred on November 21, 2024. The breach was discovered on November 29, 2024, and affected 1,434 Maine residents. The company began notifying affected individuals on March 21, 2025, and offered them 12 months of identity theft protection services through Experian IdentityWorks.
Affected (this filing): 1,434