Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
California Natural Products
bd_c1e1bfde7fc3ae94 · schema v1 · pii pii-v1
Full breach record for California Natural Products →California Natural Products notified employees of a phishing attack on its email system occurring between March 21, 2019, and April 4, 2019. The incident potentially compromised sensitive employee information, including full names, driver's license numbers, Social Security numbers, and dates of birth. The company hired forensic consultants, notified federal law enforcement, and offered one year of free identity protection services through TransUnion.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-147950
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 7, 2019
- Raw hash
- c5e055b4720b8b32e1e5d56b7248527f31e165b49cb9de149a21958bedd92b55
Reporting entity
- Name
- California Natural Productsnorm: california natural products
Victim entity
- Name
- California Natural Productsnorm: california natural products
Incident
- Discovered
- Apr 4, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.