HackingCustomer Data InvolvedIDENTITY_BASICLowContained
Pandol
bd_e9fdab9fd6595ed4 · schema v1 · pii pii-v1
Full breach record for Pandol →Pandol Brothers, Inc. notified California residents of unauthorized access to systems between March 20 and March 27, 2023. The company became aware of suspicious activity on March 27, 2023. Investigation confirmed files were accessed or copied without authorization. Affected data includes names and other personal information. The company engaged forensic specialists, secured systems, and is offering 24 months of credit monitoring.
California clockDiscovered Mar 27, 2023 → Notified Dec 11, 2023259d ✗ CA 60-day late37 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577719
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 11, 2023
- Raw hash
- 5643c24e11b749c9c3275fda5f930ec90676f454192b4fdc969da5d60c4a77a3
Reporting entity
- Name
- Pandolnorm: pandol
- Domain
- pandol.com
Victim entity
- Name
- Pandolnorm: pandol
- Domain
- pandol.com
Incident
- Discovered
- Mar 27, 2023
- Materiality determined
- —
- Notification sent
- Dec 11, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Regulator citations
- Notified applicable regulatory authorities where necessary
Compliance
- Time to disclose
- 37 weeks(259 days from discovery to filing)
- Compliance flags
- CA 60-day late · 259dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 27, 2023→ Notified: Dec 11, 2023259d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.