HackingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
BOB'S RED MILL NATURAL FOODS, INC.
bd_e2fee1411f242afb · schema v1 · pii pii-v1
Full breach record for BOB'S RED MILL NATURAL FOODS, INC. →Bob’s Red Mill Natural Foods, Inc. reported an external system breach (hacking) occurring on November 28, 2021, discovered on December 17, 2021. The incident affected 4,325 individuals, including 4 Maine residents. Compromised data included names and driver's license numbers. The company provided written notification and offered 12 months of credit monitoring and identity theft protection through IDX.
Maine clockDiscovered Dec 17, 2021 → Filed with AG Jan 19, 202233d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_380a45d9f2b5d41eMaine State AGfiled 2022-01-06(13d gap)Verified
- bd_3e729ccecdef7799Maine State AGfiled 2022-01-04(15d gap)Verified
- bd_e7adbac58dafbe9aOregon State AGfiled 2022-01-04(15d gap)Verified
- bd_a2aa8e4fe0912c52Maine State AGfiled 2021-12-23(27d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1f11c441-c1ba-474a-acf8-516de29d276e.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 19, 2022
- Raw hash
- 60232a8656ff4a511cebfd631a4ae7e6e8a29a3abe7393a04275b5ee0fdab799
Reporting entity
- Name
- Cipriani & Werner, P.C.norm: cipriani werner
Victim entity
- Name
- BOB'S RED MILL NATURAL FOODS, INC.norm: bob s red mill natural foods
Incident
- Discovered
- Dec 17, 2021
- Materiality determined
- —
- Notification sent
- Jan 4, 2021
- Affected individuals
- 4,325
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- ME AG >30d · 33d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 17, 2021→ Filed with AG: Jan 19, 202233d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.