Clustered 8 filings across 7 jurisdictions · filing window Mar 4, 2026 → Mar 9, 2026. View entity profile → Other incidents for this victim →
incident inc_8aafda3ec87f4e00 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA IN ME NH OR TX VT
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
8 filings across 7 jurisdictions · Mar 4, 2026 – Mar 9, 2026 · 3 milestones
Mar 12, 2025
When the intrusion reportedly occurred, per the linked filings
Sep 16, 2025
Reported by OREGON AG, NEW HAMPSHIRE AG filings
Feb 2, 2026
Reported by VERMONT AG, MAINE AG, TEXAS AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Service Lighting Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-12 and was reported on 2026-03-04. 410 Indiana residents were affected. 25,736 individuals affected in total.
Affected (this filing): 25,736
Service Lighting, Inc. reported that its e-commerce website was modified with malicious code to capture payment card data. The incident affected transactions made between March 12, 2025, and September 16, 2025. Affected data includes full names, payment card numbers, expiration dates, and CVV codes. The company engaged external cybersecurity professionals for a forensic investigation. No specific count of affected individuals was disclosed in the filing.
Service Lighting Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-12 and was reported on 2026-03-04. 410 Indiana residents were affected. 25,736 individuals affected in total.
Affected (this filing): 25,736
Service Lighting, Inc. notified consumers of a data breach affecting its e-commerce website. Malicious code modified the site to capture payment card data (including CVV) from transactions between March 12, 2025, and September 16, 2025. The incident was discovered via forensic investigation on February 2, 2026. No specific affected count was provided in the Vermont filing, though a separate notice for Rhode Island residents cited 95 impacted individuals.
Service Lighting, Inc. (Maple Grove, MN) discovered Feb 2, 2026 that its e-commerce site was injected with malicious code (web skimmer) capturing payment card data during checkout. Transactions Mar 12–Sep 16, 2025 were affected. Data involved: full names, card numbers, expiration dates, CVV codes. 151 Maine residents among 25,736 total individuals affected. No identity theft protection services offered.
Affected (this filing): 151
Service Lighting, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2026-03-05. The breach occurred during 3/12/2025 - 9/16/2025. The breach was discovered on 9/16/2025. 25,736 individuals were affected. Notice was sent on 3/4/2026.
Affected (this filing): 25,736
Service Lighting, Inc. based in Maple Grove, Minnesota, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-02-02 and reported on 2026-03-06. 1,748 Texas residents were affected. 25,736 individuals affected in total. Types of information involved: Name of individual;Financial Information (e.g. account number, credit or debit card number). Consumers were notified via Email.
Affected (this filing): 1,748
Service Lighting, Inc. notified the New Hampshire Attorney General of a cybersecurity incident involving its e-commerce website. Malicious code was installed to capture payment card data (names, card numbers, expiration, CVV) for transactions between March 12, 2025, and September 16, 2025. Approximately 150 New Hampshire residents were affected. Notifications were sent on March 4, 2026. No identity fraud has been reported to date.
Affected (this filing): 150