Please ensure Javascript is enabled for purposes of website accessibility

Monro names new CEO, is slapped with cyber breach lawsuit

Monro, Inc. will be undergo a "strategic review" and may be open to a sale of the company, management said in a conference call with investors. (File photo courtesy Monro, Inc.)

Monro, Inc. will be undergo a "strategic review" and may be open to a sale of the company, management said in a conference call with investors. (File photo courtesy Monro, Inc.)

Monro, Inc. will be undergo a "strategic review" and may be open to a sale of the company, management said in a conference call with investors. (File photo courtesy Monro, Inc.)

Monro, Inc. will be undergo a "strategic review" and may be open to a sale of the company, management said in a conference call with investors. (File photo courtesy Monro, Inc.)

Monro names new CEO, is slapped with cyber breach lawsuit

Listen to this article

Monro, Inc. failed to take ordinary steps to ensure that the personal information of employees and customers was protected from cyber criminals, leading to an inevitable system breach, according to a class action suit filed Monday.

UPDATE: Mandate to new Monro CEO: Enhance profits, shareholder returns

The complaint, filed in state Supreme Court in Monroe County, alleges vulnerabilities existed in ‘s email system that made it easy for hackers to obtain personal information.

The civil action came the same day Monro fired Michael Broderick as president and CEO. Peter Fitzsimmons, partner and managing director of AlixPartners, was named new president and CEO.

A company news release said the company’s board deemed that a change in leadership was necessary to “enhance operations, drive profitability and increase operating income and total shareholder returns.”

The class action lawsuit, brought on behalf of Susan J. Langenfeld and “all others similarly situated,” contends the Perinton-based auto services retailer “failed to implement practices and systems to mitigate against the risks posed by Monro’s negligent IT practices.”

As a result, the complaint says, the system hack that was discovered late last year means the plaintiff and other class members “face a litany of harms that accompany data breaches of this magnitude and severity.”

Monro advised customers on March 21 of the breach. The lawsuit says the hacker obtained names, social security numbers, addresses, dates of birth, ID numbers and health information of employees.

“As it turns out,” the complaint alleges, “this incident did not require advanced or elaborate hacking techniques. Rather, existing vulnerabilities in Monro’s IT systems were exploited in the attack.”

The lawsuit also contends Monro “had the resources to take seriously the obligation to protect private information” but chose not to “invest the resources necessary to protect the PII (personal identifiable information) of plaintiff and class members.”

Filed by attorney Israel David of the New York City-based firm of Israel David LLC, the suit says Monro is liable to plaintiffs because of a litany of negligent acts, including:

  • a failure to maintain an adequate data security system;
  • failing to implement updates and patches in a timely manner;
  • failing to monitor third-party data security systems for existing intrusions, brute-force attempts and clearing of event logs;
  • failing to update firewalls, check user account privileges or ensure property security practices;
  • failing to adequately oversee employees and third-party vendors;
  • failing to avoid the use of domain-wide, administrative-level service accounts;
  • failing to mandate the use of strong randomized, just-in-time local administrator passwords.

The lawsuit seeks unspecified compensatory and consequential damages; restitution for actual, nominal or other damages; and proceeds Monro “unjustly received” from plaintiff and class members or a refund for overpaying for Monro services.

[email protected]/(585) 653-4020

r