HackingManufacturingManufacturingCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
B&G Foods, Inc.
bd_e784507c1ab084e1 · schema v1 · pii pii-v1
Full breach record for B&G Foods, Inc. →B&G Foods, Inc. reported an external system breach (hacking) occurring between January 23, 2023, and February 7, 2023, discovered on February 5, 2023. The incident affected 918 individuals, including 112 Maine residents. Personal information compromised included names and Social Security Numbers. B&G Foods provided written notification and offered 24 months of credit monitoring through Experian.
Maine clockDiscovered Feb 5, 2023 → Filed with AG Sep 11, 2023218d ✗ ME AG >90d31 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 3 about the same incident.View merged incident
A leak claim by daixin about this victim predates this filing by 211 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_c92265254e9e3c21Leak Sitedaixinfiled 2023-02-11(211d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_47973f52580ab522New Hampshire State AGfiled 2023-09-11Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/bc56730c-f119-410b-8adc-c7903b9f7a49.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2023
- Raw hash
- b5346386f5379b9c3effa68fc6d9c588cc2f37cecb1cae957c78d305b4667f95
Reporting entity
- Name
- B&G Foods, Inc.norm: b g foods
- Domain
- bgfoods.com
Victim entity
- Name
- B&G Foods, Inc.norm: b g foods
- Domain
- bgfoods.com
- Industry
- Manufacturingnaics map
Incident
- Discovered
- Feb 5, 2023
- Materiality determined
- —
- Notification sent
- Sep 11, 2023
- Affected individuals
- 918
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 31 weeks(218 days from discovery to filing)
- Compliance flags
- ME AG >90d · 218dME resident >180d · 218dLeak >180d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 5, 2023→ Filed with AG: Sep 11, 2023218d 90 days ME AG >90d Maine Discovered: Feb 5, 2023→ Notified: Sep 11, 2023218d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.