Crystal Creamery
bd_33481b91b78b0372 · schema v1 · pii pii-v1
Full breach record for Crystal Creamery →Crystal Creamery, Inc. notified the California Attorney General of a data breach where an unknown external actor accessed their network on or before January 13, 2023. The company identified unusual activity on January 14, 2023. The investigation determined that certain files containing names and other data elements may have been viewed or downloaded without authorization. The company engaged outside cybersecurity specialists, implemented additional technical security measures, and is offering one year of complimentary credit monitoring through Experian to affected individuals.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-563871
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 3, 2023
- Raw hash
- 6e3acf472aece779a0a07c36242596a72e0c38c3ef91361e0a248359b518f9fb
Reporting entity
- Name
- Crystal Creamerynorm: crystal creamery
- Domain
- crystalcreamery.com
Victim entity
- Name
- Crystal Creamerynorm: crystal creamery
- Domain
- crystalcreamery.com
Incident
- Discovered
- Jan 14, 2023
- Materiality determined
- —
- Notification sent
- Mar 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 48d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 14, 2023→ Notified: Mar 3, 202348d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.