Social EngineeringPhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICHighResolved
DRISCOLL'S, INC.
bd_fbfb3f21b11777b1 · schema v1 · pii pii-v1
Full breach record for DRISCOLL'S, INC. →Driscoll’s, Inc. reported a data breach affecting 1,384 California residents. Unauthorized access to employee email accounts occurred between July 17 and August 18, 2017, following a phishing campaign that compromised payroll credentials. The incident exposed names, SSNs, driver's licenses, passport numbers, financial account details, and health information. Driscoll's engaged forensic investigators, reset passwords, and provided one year of credit monitoring to affected individuals.
California clockDiscovered Jul 28, 2017 → Notified Feb 9, 2018196d ✗ CA 60-day late29 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,384 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-133736
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 13, 2018
- Raw hash
- 4c470e47119e883a5c3ed00dba7dc0eb07ba48f71baea5a35d89b1cc8531b6e7
Reporting entity
- Name
- DRISCOLL'S, INC.norm: driscoll s
Victim entity
- Name
- DRISCOLL'S, INC.norm: driscoll s
Incident
- Discovered
- Jul 28, 2017
- Materiality determined
- Dec 18, 2017
- Notification sent
- Feb 9, 2018
- Affected individuals
- 1,384
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Providing written notice of this incident to other state regulators as necessary
- Initial access
- phishing_link
Compliance
- Time to disclose
- 29 weeks(200 days from discovery to filing)
- Compliance flags
- CA 60-day late · 196d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 28, 2017→ Notified: Feb 9, 2018196d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.