What Happened?
On August 25, 2025, ScrogginsGrear experienced unauthorized access to a single employee email account within its cloud-based email environment (email tenant). ScrogginsGrear discovered the incident on September 10, 2025, when it detected potentially anomalous activity in its email tenant. Upon learning of the incident, ScrogginsGrear launched an investigation and engaged cybersecurity experts to understand the scope of the issue. The investigation determined that an unknown third party gained unauthorized access to one employee mailbox; according to the company, no other systems or email accounts were affected. After reviewing the contents of the affected mailbox, ScrogginsGrear determined that personal information and protected health information may have been exposed for affected individuals. ScrogginsGrear began preparing notifications and sent written notice letters dated April 7, 2026. The incident was also disclosed through filings/notifications with state regulators including the Indiana Attorney General, the Maine Attorney General, and the Massachusetts Office of Consumer Affairs and Business Regulation, and ScrogginsGrear posted a public notice on its website. The company reported the incident impacted 8,919 individuals in the United States (including 240 Indiana residents, 10 Massachusetts residents, and 4 Maine residents).