Clustered 7 filings across 7 jurisdictions · filing window Apr 29, 2024 → Apr 30, 2024. View entity profile → Other incidents for this victim →
incident inc_bcbe2ddc59684fcd · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA ME MT NH OR VT WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Mar 7, 2024 → Mar 11, 2024
When the intrusion reportedly occurred, per the linked filings
Mar 10, 2024
Reported by NEW HAMPSHIRE AG, OREGON AG, CALIFORNIA AG, WASHINGTON AG, VERMONT AG, MAINE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Panda Restaurant Group, Inc. reported a data security incident affecting corporate systems. Unauthorized access occurred between March 7-11, 2024, detected on March 10, 2024. The incident involved personal information including names combined with other identifiers. Panda engaged third-party cybersecurity experts and law enforcement, implemented additional technical safeguards, and offered credit monitoring services to affected individuals.
Panda Restaurant Group, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2024-04-30. The breach occurred from 3/7/2023 to 3/11/2024. 959 Montana residents were affected.
Affected (this filing): 959
Panda Restaurant Group, Inc. (PRG) reported a data breach to the Oregon Attorney General. The breach was reported on 2024-04-30. The breach occurred during 3/7/2024 - 3/11/2024. The breach was discovered on 3/10/2024. 239,815 individuals were affected. Notice was sent on 4/30/2024.
Affected (this filing): 239,815
Panda Restaurant Group, Inc. (PRG) experienced an external system breach on March 7, 2024, which was discovered on March 10, 2024. The breach affected 64 Maine residents, compromising their names and driver's license or non-driver identification card numbers. PRG notified the affected individuals on April 30, 2024, and offered identity theft protection services through Epiq eDiscovery Solutions.
Affected (this filing): 64
Panda Restaurant Group, Inc. detected a data security incident on March 10, 2024, impacting corporate systems. An unauthorized actor accessed certain information between March 7-11, 2024. Affected data includes names and potentially Social Security Numbers. The company secured its environment, engaged third-party cybersecurity experts, and worked with law enforcement. Credit monitoring services are being offered to affected individuals.
Panda Restaurant Group, Inc. (PRG), a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2024-03-10 and filed notice on 2024-04-30. 6,916 Washington residents were affected. 51 days elapsed between awareness and notification. 3 days to identify the breach. 1 days to contain the breach.
Affected (this filing): 6,916
Panda Restaurant Group, Inc. notified consumers of a data security incident detected on March 10, 2024. Unauthorized access occurred between March 7-11, 2024, affecting personal information including names and government identifiers (SSN, driver's license). The company engaged third-party cybersecurity experts and law enforcement, implemented technical safeguards, and offered credit monitoring services.