HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
B&G Foods, Inc.
bd_47973f52580ab522 · schema v1 · pii pii-v1
Full breach record for B&G Foods, Inc. →B&G Foods, Inc. notified the New Hampshire Attorney General of a cybersecurity incident occurring between January 23 and February 7, 2023. An unauthorized third party gained access to systems via indiscriminate cyber-attacks, accessing employee data files containing personal information. B&G discovered the intrusion on February 12, 2023. The breach affected 3 New Hampshire residents. B&G engaged third-party experts, notified law enforcement, implemented MFA, and offered credit monitoring services to affected individuals.
Leak gap clock✗ Leak >180d30 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by daixin about this victim predates this filing by 211 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_c92265254e9e3c21Leak Sitedaixinfiled 2023-02-11(211d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_e784507c1ab084e1Maine State AGfiled 2023-09-11Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/b-g-foods-20230911.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2023
- Raw hash
- 62d6aca4714ddd3653f6bb5812784cda343319cc00ff356ad62c5fa620942f47
Reporting entity
- Name
- B&G Foods, Inc.norm: b g foods
- Domain
- bgfoods.com
Victim entity
- Name
- B&G Foods, Inc.norm: b g foods
- Domain
- bgfoods.com
Incident
- Discovered
- Feb 12, 2023
- Materiality determined
- —
- Notification sent
- Sep 11, 2023
- Affected individuals
- 3
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 30 weeks(211 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.