HackingSupply Chain (3P Vendor)Employee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENTMediumContained
MONDELEZ GLOBAL LLC
bd_820d6b50821eff43 · schema v1 · pii pii-v1
Full breach record for MONDELEZ GLOBAL LLC →Mondelez Global LLC notified employees of a data breach involving their law firm, Bryan Cave Leighton Paisner LLP. Unauthorized access to Bryan Cave's systems occurred between February 23 and March 1, 2023, and was detected on February 27, 2023. The incident exposed personal information of current and former employees, including Social Security numbers, names, addresses, dates of birth, and retirement plan information. Mondelez offered 24 months of credit monitoring.
California clockDiscovered Feb 27, 2023 → Notified Jun 15, 2023108d ✗ CA 60-day late16 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_8fc3c30a7b89ff66Washington State AGfiled 2023-06-20Verified
- bd_b7de965a48342f55Oregon State AGfiled 2023-06-19(1d gap)Verified
- bd_a4506857adbf9ea7Maine State AGfiled 2023-06-15(5d gap)Verified
- bd_f49f3eaaf355d387Montana State AGfiled 2023-06-15(5d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_fac3e2b9089e310cNew Hampshire State AGfiled 2023-06-15(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-568259
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 20, 2023
- Raw hash
- 7769aecd9692820d2d9c54e85b56e0cf5795bf3ceac602150c821ab8ef86424a
Reporting entity
- Name
- MONDELEZ GLOBAL LLCnorm: mondelez global
Victim entity
- Name
- MONDELEZ GLOBAL LLCnorm: mondelez global
Incident
- Discovered
- Feb 27, 2023
- Materiality determined
- —
- Notification sent
- Jun 15, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Bryan Cave Leighton Paisner LLP
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 16 weeks(113 days from discovery to filing)
- Compliance flags
- CA 60-day late · 108d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 27, 2023→ Notified: Jun 15, 2023108d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.