Clustered 5 filings across 5 jurisdictions · filed Sep 19, 2016. View entity profile → Other incidents for this victim →
incident inc_8e36b943b38a4ae1 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA MT NH OR WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Aug 22, 2016
When the intrusion reportedly occurred, per the linked filings
Aug 22, 2016
Reported by CALIFORNIA AG, OREGON AG, NEW HAMPSHIRE AG, WASHINGTON AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
ACTIVEOutdoors disclosed unauthorized access to its online hunting and fishing licensing applications in Idaho, Oregon, and Washington. The company became aware of the incident on August 22, 2016. Affected data included names, addresses, dates of birth, driver's license numbers, and Social Security numbers for accounts created prior to 2006/2007. No financial data was involved. The company engaged a cybersecurity firm, coordinated with state agencies, and offered two years of identity protection services to affected individuals.
ACTIVEOutdoors reported a data breach to the Oregon Attorney General. The breach was reported on 2016-09-19. The breach was discovered on 8/22/2016. 4,210,850 individuals were affected. Notice was sent on 9/19/2016.
Affected (this filing): 4,210,850
ACTIVEOutdoors reported a data breach to the Montana Attorney General. The breach was reported on 2016-09-19. The breach occurred on 8/22/2016. 40,370 Montana residents were affected.
Affected (this filing): 40,370
ACTIVEOutdoors, provider of online state hunting and fishing license applications, notified New Hampshire AG on September 19, 2016, of unauthorized access to its Affected Applications discovered on August 22, 2016. The incident potentially exposed personal information of 1,282 New Hampshire residents, including names, addresses, DOBs, and driver's license numbers, with 304 residents having full SSNs exposed. The threat was isolated to accounts created prior to July 2006/2007. ACTIVEOutdoors engaged a cybersecurity firm, secured the applications, and provided 24 months of identity repair and credit monitoring services to affected individuals.
Affected (this filing): 1,282
ACTIVEOutdoors, a government sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2016-08-22 and filed notice on 2016-09-19. 1,449,645 Washington residents were affected. 28 days elapsed between awareness and notification.
Affected (this filing): 1,449,645