DisclosureLens
HackingManufacturingManufacturingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)MediumContained

Mead Johnson & Company, LLC

bd_bfa641e8a3c4ab41 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 20, 2020

Filed

Mar 10, 2021

To disclose

16 weeks

Affected

2,828state residents only

Confidence

70%
Full breach record for Mead Johnson & Company, LLC

Mead Johnson & Company, LLC reported a data breach involving its vendor ActiveProspect, Inc. on March 10, 2021. Unauthorized access occurred Nov 7-8, 2020, using an employee's credentials. 2,828 Washington residents had their names and DOB exposed. ActiveProspect detected the breach on Nov 20, 2020. Remediation included credential resets, safeguards, and 12 months of credit monitoring for affected individuals.

Washington clock WA AG >90d16 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 13 days
discovery → filing · 16 weeks / 110 days

Nov 7, 2020

Begins

Nov 20, 2020

Discovered

Mar 10, 2021

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,828 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.