Clustered 3 filings across 3 jurisdictions · filing window Dec 19, 2024 → Dec 27, 2024. View entity profile → Other incidents for this victim →
incident inc_aadf25d885d04eb2 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA ME WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
May 13, 2024
When the intrusion reportedly occurred, per the linked filings
Aug 9, 2024
Reported by WASHINGTON AG, MAINE AG, CALIFORNIA AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
HRB Tax Group, Inc., a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2024-08-09 and filed notice on 2024-12-19. 889 Washington residents were affected. 132 days elapsed between awareness and notification. 88 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 889
HRB Tax Group, Inc. reported a data breach affecting 24 Maine residents. The breach occurred on May 13, 2024, and was discovered on August 9, 2024. Affected individuals were notified on November 26, 2024, and offered 24 months of identity protection services through IDX.
Affected (this filing): 24
H&R Block notified customers that an unauthorized third party used personally identifiable information obtained from external sources to access client accounts between May 13, 2024, and August 7, 2024. The incident was discovered on August 9, 2024. Affected data may include names, Social Security numbers, ITINs, government-issued ID numbers, financial account information, and dates of birth. H&R Block engaged third-party experts, terminated unauthorized access, and is offering 24 months of identity theft protection services.