
In late 2024, Monro, Inc. discovered suspicious activity involving an employee's email. Upon noticing this unusual activity, the company began an investigation.
The investigation revealed that between November 21, 2024, and a limited period thereafter, an unauthorized individual accessed the employee's email account and selected files within it.
The company conducted a thorough review of the affected mailbox, which concluded around January 28, 2025. This review determined that the data breach potentially exposed sensitive personally identifiable information (PII) and certain protected health information (PHI) of 112,458 Americans.
Information Exposed:
Monro, Inc. reported this data breach to several state attorneys general offices, including California, South Carolina, and New Hampshire.
Impact by State:
Monro is providing affected individuals with complimentary access to Experian IdentityWorks for 12 months. Individuals affected by the breach are encouraged to enroll in this service by May 30, 2025, using the activation instructions provided in the notification letter.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)