HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumContained
Spring Mountain Vineyard
bd_1accb6d30abb61f4 · schema v1 · pii pii-v1
Full breach record for Spring Mountain Vineyard →Spring Mountain Vineyard notified customers of a data breach involving its third-party provider, Missing Link Networks Inc. The incident occurred between April 1 and April 30, 2015, and was discovered on May 27, 2015. The breach exposed customer names, credit/debit card numbers, billing addresses, passwords, and dates of birth. Missing Link has contained the compromise and is converting to a tokenization system. Spring Mountain Vineyard engaged Experian to provide one year of complimentary identity protection services to affected customers.
California clockDiscovered May 27, 2015 → Notified Jun 10, 201514d ✓ CA 60-day OK22 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-56460
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 18, 2015
- Raw hash
- a940c8291426e3f0e6c1fbfef8fcbe66b3fe500a425972b828eceb7fcec23537
Reporting entity
- Name
- Spring Mountain Vineyardnorm: spring mountain vineyard
- Domain
- springmtn.com
Victim entity
- Name
- Spring Mountain Vineyardnorm: spring mountain vineyard
- Domain
- springmtn.com
Incident
- Discovered
- May 27, 2015
- Materiality determined
- —
- Notification sent
- Jun 10, 2015
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Missing Link Networks Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 14d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 27, 2015→ Notified: Jun 10, 201514d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.