What Happened?
**__What Happened?__**nnScrogginsGrear Inc. reported that it detected potentially anomalous activity in its cloud-based email environment (its “email tenant”) on September 10, 2025. Upon learning of the incident, ScrogginsGrear launched an investigation and engaged third-party cybersecurity experts to help determine the nature and scope of the incident.nnThe investigation concluded that an unknown third party gained unauthorized access to a single employee email account within ScrogginsGrear’s email system on August 25, 2025. According to ScrogginsGrear, no other systems or email accounts were affected beyond the single mailbox.nnAfter reviewing the contents of the affected mailbox, ScrogginsGrear determined that personal information (including protected health information) may have been exposed. ScrogginsGrear began preparing notices and sent written notification letters to affected individuals dated April 7, 2026.nnScrogginsGrear disclosed the incident through filings/notifications with state regulators, including the Indiana Attorney General, the Maine Attorney General, and the Massachusetts Office of Consumer Affairs and Business Regulation, and also posted a notice on its website (https://scroggins.com/data-incident/). The materials provided indicate the incident affected 8,919 individuals in the United States (including 240 Indiana residents, ten Massachusetts residents, and four Maine residents).