Clustered 4 filings across 4 jurisdictions · filed Mar 2, 2023. View entity profile → Other incidents for this victim →
incident inc_5138fecd32554fab · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Financial account · Authentication
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA ME MT NH
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Dec 18, 2022
When the intrusion reportedly occurred, per the linked filings
Feb 12, 2023
Reported by NEW HAMPSHIRE AG, MAINE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Chick-fil-A, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-03-02. The breach occurred from 12/18/2022 to 2/12/2023. 31 Montana residents were affected.
Affected (this filing): 31
Chick-fil-A, Inc. disclosed that unauthorized parties launched an automated attack against its website and mobile application between December 18, 2022, and February 12, 2023. The attackers used account credentials (email addresses and passwords) obtained from a third-party source to access Chick-fil-A One accounts. Affected data included names, email addresses, membership numbers, masked payment card numbers, and potentially phone numbers and addresses. Chick-fil-A responded by resetting passwords, removing stored payment methods, and freezing account funds.
Chick-fil-A, Inc. notified the NH Attorney General of a data security incident involving unauthorized access to Chick-fil-A One accounts. Attackers used stolen credentials from a third-party source to access customer data between Dec 18, 2022 and Feb 12, 2023. 82 NH residents were affected. Data included credentials, payment info, and account balances. Chick-fil-A engaged forensic investigators, reset passwords, and froze funds.
Affected (this filing): 82
Chick-fil-A, Inc. disclosed a data breach affecting 61 Maine residents. The breach, which occurred between December 18, 2022, and February 12, 2023, was discovered on February 12, 2023. The incident was categorized as an external system breach or hacking, resulting in the compromise of customers' names and financial account information, including credit/debit card numbers along with their security codes or PINs. Affected individuals were notified electronically on March 2, 2023.
Affected (this filing): 61