Clustered 4 filings across 4 jurisdictions · filing window Dec 16, 2022 → Apr 6, 2023. View entity profile → Other incidents for this victim →
incident inc_336115f3956a4f64 · merge_method llm · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Gap between first leak claim and first regulatory filing
Discovery to SEC materiality determination
Materiality determination to SEC 8-K filing
Time between earliest and latest filing
Identity (basic) · Government ID
CA FEDERAL ME
Leak Site · SEC 8-K · State AG
Earliest sighting first · deep chronology in Litigation Timeline
Oct 13, 2022 → Nov 29, 2022
When the intrusion reportedly occurred, per the linked filings
Nov 5, 2022
Reported by CALIFORNIA AG, SEC 8-K filings
Mar 3, 2023
Reported by MAINE AG filing
Apr 3, 2023
Registrant determined the incident material — starts the SEC 4-business-day clock
PGT Innovations experienced an external system breach between October 13, 2022, and November 29, 2022, discovered on March 3, 2023. The breach compromised names and Social Security numbers. The company began notifying affected individuals on April 3, 2023, and offered 12 months of credit monitoring services through Experian.
Affected (this filing): 1
PGT Innovations detected unauthorized access to its network on November 5, 2022. A subsequent forensic investigation determined that an unauthorized party potentially removed files containing personal information (names) between October 13, 2022, and November 29, 2022. The company contained the threat, restored data, notified law enforcement, and engaged external cybersecurity professionals. Complimentary credit monitoring was offered to affected individuals.
PGT Innovations, Inc. filed an 8-K on April 6, 2023, disclosing a ransomware infection detected on November 5, 2022. The incident impacted network operations and resulted in the unauthorized access of current and former employee personal information. The Company engaged forensic experts, notified affected individuals and regulators starting April 3, 2023, and maintains cyber insurance.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.