HackingRetail & ConsumerRetailCustomer Data InvolvedDelayed DiscoveryPIILowContained
Epi Breads
bd_95ecdef2bec3dbf8 · schema v1 · pii pii-v1
Full breach record for Epi Breads →EPI Breads, an Atlanta-based food company, experienced an external system breach (hacking) beginning around August 22, 2024. Unusual activity was discovered in their network and investigation concluded September 17, 2024, confirming unauthorized access or acquisition of personal data. Three Maine residents were affected out of 10,853 total. The company engaged cybersecurity experts, secured its network, and offered 12 months of free credit monitoring via Cyberscout/TransUnion.
Maine clockDiscovered Sep 17, 2024 → Filed with AG Nov 4, 202448d ⏱ ME AG >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by play about this victim predates this filing by 75 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_8ac0d56e42cb9bfdVermont State AGfiled 2024-11-04Verified
- bd_dbf6b1a476086b89New Hampshire State AGfiled 2024-11-04Verified
- bd_78b7772be460e7b7Indiana State AGfiled 2024-10-30(5d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/e4639d2d-5236-42ce-b346-fb892d7dfcf4.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 4, 2024
- Raw hash
- cc506f72f6c5808d41b834891d2fc48d126879bd59b3d547c6288d2db9449ebd
Reporting entity
- Name
- Epi Breadsnorm: epi breads
- Domain
- epibreads.com
Victim entity
- Name
- Epi Breadsnorm: epi breads
- Domain
- epibreads.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Sep 17, 2024
- Materiality determined
- —
- Notification sent
- Oct 30, 2024
- Affected individuals
- 3
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Maine Attorney General
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- ME AG >30d · 48dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Sep 17, 2024→ Filed with AG: Nov 4, 202448d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.