HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
FARMER BROS. CO.
bd_17d44ae703b94bf8 · schema v1 · pii pii-v1
Full breach record for FARMER BROS. CO. →Farmer Bros. Co. reported that on September 18, 2018, it became aware that multiple company email accounts were accessed by an unauthorized third party. The breach date listed by the CA AG is May 1, 2018. The investigation concluded in November 2018. Affected data may include names, addresses, SSNs, driver's license numbers, payment card numbers, CVVs, bank account numbers, and routing numbers. The company engaged a cyber incident response team and enhanced email security protections. Identity theft protection services were offered to affected individuals.
California clockDiscovered Sep 18, 2018 → Notified Dec 11, 201884d ✗ CA 60-day late12 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-142591
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 11, 2018
- Raw hash
- 0cf18eda81667aa19b0ef2569d09a27e6981ee83d560b3d4f9369a393a90b92d
Reporting entity
- Name
- FARMER BROS. CO.norm: farmer bros
Victim entity
- Name
- FARMER BROS. CO.norm: farmer bros
Incident
- Discovered
- Sep 18, 2018
- Materiality determined
- —
- Notification sent
- Dec 11, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(84 days from discovery to filing)
- Compliance flags
- CA 60-day late · 84d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 18, 2018→ Notified: Dec 11, 201884d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.