HackingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Farmer Brothers Company
bd_557b222edc9b4bbd · schema v1 · pii pii-v1
Full breach record for Farmer Brothers Company →Farmer Brothers Company notified California residents of unauthorized access to archived files between March 6 and March 14, 2025. The company identified indications of potential unauthorized access on March 14, 2025. Personal information involved includes basic identity data. The company secured systems, reported to law enforcement, and is offering 12 months of credit monitoring.
California clockDiscovered Mar 14, 2025 → Notified Sep 9, 2025179d ✗ CA 60-day late26 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_2346ff290be14cdbVermont State AGfiled 2025-09-09Verified
- bd_4bcd2385a0817f7dOregon State AGfiled 2025-09-09Candidate
- bd_a19ba8de6f2b3f9bMaine State AGfiled 2025-09-09Verified by operator
- bd_bf5d5f7c554e3c44Montana State AGfiled 2025-09-09Verified by operator
Show 4 more filings ↓Show fewer ↑up to 1d gap
- bd_d19f1c0203deb124Indiana State AGfiled 2025-09-09Verified
- bd_ff0874b846405f0eNew Hampshire State AGfiled 2025-09-09Verified
- bd_611ab6b8e533b454Washington State AGfiled 2025-09-10(1d gap)Verified by operator
- bd_6975b4edc70a9985Texas State AGfiled 2025-09-10(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-608356
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 9, 2025
- Raw hash
- d9c773cde902d1cff3f361b26c6b39f6966aa9241b2311b53ad0ad236af2f93e
Reporting entity
- Name
- Farmer Brothers Companynorm: farmer brothers
- Domain
- farmerbros.com
Victim entity
- Name
- Farmer Brothers Companynorm: farmer brothers
- Domain
- farmerbros.com
Incident
- Discovered
- Mar 14, 2025
- Materiality determined
- —
- Notification sent
- Sep 9, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unknown
- Threat actor
- External
- Regulator citations
- Reported this event to federal law enforcement
Compliance
- Time to disclose
- 26 weeks(179 days from discovery to filing)
- Compliance flags
- CA 60-day late · 179d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 14, 2025→ Notified: Sep 9, 2025179d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.