Confirmed breach. Intrusion Jan 22, 2025, discovered Jan 26, 2025 — the first regulatory filing landed 44 days later. 33 individuals reported across the linked filings.
Connecticut Container Corporation d/b/a Unicorr Packaging Group notified the Maryland AG of a data security incident discovered on Jan 26, 2025. Unauthorized access to the network potentially impacted 33 individuals (1 in MD, 32 in RI) with names and SSNs. Response included forensic investigation, password resets, and 24 months of credit monitoring.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Unicorr Packaging Group (CT) suffered an external network intrusion detected Jan 26, 2025 (occurrence Jan 22, 2025). Forensic investigation confirmed unauthorized data access; materiality determined Feb 19, 2025. Impacted data includes names plus additional personal identifiers. 1 of 1,260 total affected individuals was a Maine resident. Passwords reset, accounts secured. IDX 24-month credit monitoring offered.
Affected (this filing): 1
ME AG >30d · 44d
🍁Vermont State AGlinked via multistate filing link · 100%
Connecticut Container Corporation d/b/a Unicorr Packaging Group notified consumers on March 11, 2025, of unauthorized network access discovered on January 26, 2025. The incident impacted names combined with government identifiers (e.g., SSN). 32 Rhode Island residents were explicitly identified; other states notified. The company engaged forensic specialists, reset passwords, and offered 24 months of credit monitoring.