HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTCREDENTIALSMediumContained
THE HERSHEY COMPANY
bd_3f641e1fa342eece · schema v1 · pii pii-v1
Full breach record for THE HERSHEY COMPANY →The Hershey Company notified consumers of a security incident between Sept 3-4, 2023, where an unauthorized user accessed limited email accounts. Data accessed included names, SSNs, health info, driver's licenses, and financial credentials. Hershey engaged forensic investigators, blocked access, and offered 24 months of Experian IdentityWorks. No evidence of misuse was found.
Vermont clock✗ VT AG >45 bday13 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c75b9d05902bdbdbMaine State AGfiled 2023-12-01Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-01-hershey-company-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 1, 2023
- Raw hash
- 610732ae5f570fa413f7b44d36ed136e7ab570f52d0d27eb40bc626b876b81fd
Reporting entity
- Name
- THE HERSHEY COMPANYnorm: the hershey
Victim entity
- Name
- THE HERSHEY COMPANYnorm: the hershey
Incident
- Discovered
- Sep 3, 2023
- Materiality determined
- —
- Notification sent
- Dec 1, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(89 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.