HackingManufacturingRetail & ConsumerManufacturingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedEmployee Data InvolvedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumContained
WK KELLOGG CO
bd_33282fd020487c03 · schema v1 · pii pii-v1
Full breach record for WK KELLOGG CO →WK Kellogg Co. notified Maine (1 resident) and Rhode Island (1 individual) of a security incident involving its secure file transfer vendor, Cleo. An unauthorized actor gained access on December 7, 2024 to Cleo-hosted servers used to transfer employee files to HR service vendors. WK Kellogg discovered the incident on February 27, 2025. Exposed data included names and Social Security numbers. Affected individuals were offered one year of Kroll credit monitoring and identity protection services.
Maine clockDiscovered Feb 27, 2025 → Filed with AG Apr 4, 202536d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 36 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_6d36243d4b4a9ca6Leak Sitecl0pfiled 2025-02-27(36d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_5274f974c8dcc383Indiana State AGfiled 2025-04-04Verified
- bd_8aaba010cf1da3a8New Hampshire State AGfiled 2025-04-04Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/9b6116f8-043e-40c5-a210-c152d4edfa95.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 4, 2025
- Raw hash
- 33a86202cfcd999d10d72eb3740ecd6610394346cb62ac167a7342a92593ed68
Reporting entity
- Name
- WK KELLOGG COnorm: wk kellogg
- Domain
- wkkellogg.com
Victim entity
- Name
- WK KELLOGG COnorm: wk kellogg
- Domain
- wkkellogg.com
- Industry
- Food Manufacturing
- Industry
- ManufacturingllmRetail & Consumerllm
Incident
- Discovered
- Feb 27, 2025
- Materiality determined
- —
- Notification sent
- Apr 4, 2025
- Affected individuals
- 1
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maine Attorney General per Me. Rev. Stat. Tit. 10, §1348
- Third party
- via Cleo
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- ME AG >30d · 36dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 27, 2025→ Filed with AG: Apr 4, 202536d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.