HackingData ExfiltratedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Herff Jones, Inc.
bd_2e90ae60839167cf · schema v1 · pii pii-v1
Full breach record for Herff Jones, Inc. →Herff Jones, LLC reported a data breach affecting customer payment card information and PII. The incident was discovered on April 7, 2021, involving unauthorized access to payment systems. Herff Jones engaged a cybersecurity firm, notified law enforcement, and offered one year of credit monitoring to affected individuals.
California clockDiscovered Apr 7, 2021 → Notified Apr 7, 20210d ✓ CA 60-day OK10 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_c3551e4927f858b9Oregon State AGfiled 2021-06-16Verified
- bd_c498cc7962b75b4eMaine State AGfiled 2021-06-17(1d gap)Verified
- bd_29c004d8b0b0569aMontana State AGfiled 2021-06-15(1d gap)Candidate
- bd_b365bf4fbdc559d8Delaware State AGfiled 2021-06-15(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 2d gap
- bd_d19b69aaa264a9e5Delaware State AGfiled 2021-06-15(1d gap)Verified
- bd_5f73094a967c585aWashington State AGfiled 2021-06-18(2d gap)Verified
- bd_74f29caa55e60387Hawaii State AGfiled 2021-06-18(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541930
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 16, 2021
- Raw hash
- 965ff7b049bd527f19efaf6e04970fe96488d9575406b0066bffa4dd8246e6ec
Reporting entity
- Name
- Herff Jones, Inc.norm: herff jones
Victim entity
- Name
- Herff Jones, Inc.norm: herff jones
Incident
- Discovered
- Apr 7, 2021
- Materiality determined
- Apr 7, 2021
- Notification sent
- Apr 7, 2021
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 7, 2021→ Notified: Apr 7, 20210d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.