DisclosureLens
Social EngineeringRetail & ConsumerRetailPhishingBECCustomer Data InvolvedTargetedPIICredentialsMediumContained

U.S. Waffle Inc

bd_cae19c42d35cb7c5 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Sep 26, 2023

To disclose

Affected

2,558state residents only

Linked

3 filings

Confidence

65%
Full breach record for U.S. Waffle Inc

U.S. Waffle, Inc. reported a security event where an employee email account was accessed by an unauthorized actor between January 18, 2023, and March 3, 2023. The actor likely used phishing to gain access and attempted to redirect payments. Personal information in the affected accounts may have been downloaded. The company engaged forensic experts, coordinated with law enforcement, and offered two years of complimentary identity monitoring.

South Carolina clock SC CRA notice due
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.

Incident timeline

Jan 18, 2023

Begins

Sep 26, 2023

Filed

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Massachusetts State AGSep 26 · first
Maine State AGSep 26 · first
South Carolina State AGSep 26 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.