MarineMax
Clustered 6 filings across 4 jurisdictions · filing window Mar 10, 2024 → Jul 16, 2024. View entity profile → Other incidents for this victim →
incident inc_369379d40eb94b60 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Gap between first leak claim and first regulatory filing
Discovery to SEC materiality determination
Materiality determination to SEC 8-K filing
Time between earliest and latest filing
PII
CA FEDERAL ME
Leak Site · SEC 8-K · State AG
Earliest sighting first · deep chronology in Litigation Timeline
Mar 10, 2024
When the intrusion reportedly occurred, per the linked filings
Mar 10, 2024
Reported by SEC 8-K, MAINE AG filings
Mar 10, 2024
Registrant determined the incident material — starts the SEC 4-business-day clock
MarineMax
On March 10, 2024, MarineMax, Inc. determined that a third party gained unauthorized access to portions of its information environment. The company initiated incident response and business continuity protocols, took containment measures (which caused some business disruption), engaged cybersecurity experts, and notified law enforcement. The company states it does not maintain sensitive data in the impacted environment. Investigation is ongoing; no material impact determined as of filing.
MarineMax
MarineMax, Inc. (NYSE: HZO), a recreational boat and yacht retailer, disclosed on March 12, 2024 (amended April 1, 2024) that a cybercrime organization gained unauthorized access to portions of its information environment associated with its retail business. The threat actor exfiltrated limited customer and employee personally identifiable information. The company contained the incident, remediated the affected environment, notified law enforcement, and planned to notify affected parties and regulators.
MarineMax, Inc. (Clearwater, FL) experienced an external system breach (hacking) on March 10, 2024, discovered the same day. A total of 123,494 individuals were affected nationally, including 153 Maine residents. Affected individuals were notified on July 16, 2024 and offered 24 months of Experian IdentityWorks identity monitoring services. The notice does not specify data types compromised or name a threat actor.
MarineMax, Inc. reported a data security breach to the California Attorney General. The incident occurred between March 1, 2024, and March 10, 2024. The notification letter indicates that affected individuals' information may include names, addresses, and Social Security numbers. MarineMax is offering 24 months of complimentary identity monitoring services through Experian IdentityWorks to affected individuals. The specific cause of the breach and the number of affected individuals are not detailed in the provided documents.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Affected (this filing): 153