HackingRetail & ConsumerRetailCapture App DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumResolved
International Coffee & Tea
bd_7aa3405e4ee0c847 · schema v1 · pii pii-v1
Full breach record for International Coffee & Tea →International Coffee & Tea, LLC (The Coffee Bean & Tea Leaf) notified 11 Maine residents of a data breach involving unauthorized access to company systems and limited email accounts occurring between April 5 and August 29, 2024. The breach was discovered on June 6, 2024. Information potentially accessed included names and Social Security numbers. The company offered 12 months of free credit monitoring via Equifax. Total individuals affected: 53,901.
Maine clockDiscovered Jun 6, 2024 → Filed with AG Dec 19, 2024196d ✗ ME AG >90d28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6eb0988796a6fed9Indiana State AGfiled 2024-12-19Verified
- bd_b89a0e432cce2185Oregon State AGfiled 2024-12-19Verified by operator
- bd_bd7616f55fb17fbfVermont State AGfiled 2024-12-20(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/dbe6470f-6ab9-437a-a666-ccd740e32e34.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2024
- Raw hash
- 226556191da5ed28663d0eedf0582002254e776eceeec31526a3ef8d8f2a80b6
Reporting entity
- Name
- International Coffee & Teanorm: international coffee tea
- Domain
- jollibeefoods.com
- Industry
- Food and Beverage / Retail
Victim entity
- Name
- International Coffee & Teanorm: international coffee tea
- Domain
- jollibeefoods.com
- Industry
- Food and Beverage / Retail
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Jun 6, 2024
- Materiality determined
- —
- Notification sent
- Dec 19, 2024
- Affected individuals
- 11
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified Maine Attorney GeneralNotified federal law enforcementNotified three major credit reporting agencies (Equifax, Experian, TransUnion)
Compliance
- Time to disclose
- 28 weeks(196 days from discovery to filing)
- Compliance flags
- ME AG >90d · 196dME resident >180d · 196d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 6, 2024→ Filed with AG: Dec 19, 2024196d 90 days ME AG >90d Maine Discovered: Jun 6, 2024→ Notified: Dec 19, 2024196d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.