DisclosureLens
Leak SiteState AGConfirmed4 filings · 2 statesLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforceddispossessorlow sensitivity
Merged incident · 4 filings

Crystal Creamery — January 2023 breach

Clustered 4 filings across 3 jurisdictions · filing window Feb 3, 2023 Apr 14, 2023. View entity profile → Other incidents for this victim →

affected count agreeMerge100%

Determination

Confirmed

Members

4 filings

States

2

Affected · reported

2,349

First → last filing

Feb 3, 2023 Apr 14, 2023

Merge confidence

100%

incident inc_5cb0c352e5c14386 · merged by human · confidence 100%

Confirmed breach. Merged as one breach: 2 regulatory filings and 2 unverified claims. The filing describes hacking. Intrusion Jan 13, 2023–Jan 14, 2023, discovered Jan 14, 2023 — the first regulatory filing landed 48 days later. 2,349 individuals reported across the linked filings. Data reported: Identity (basic). Each member filing remains the legal record for its jurisdiction.

Litigation Timing

Notification delay
48days

Discovered → first regulatory filing

Leak precedence
28days before filing

Days between the first leak-site claim and the first regulatory filing. Positive = the claim came first (public exposure before disclosure). Negative = the claim trailed the filing, so there was no pre-disclosure leak. Counts regulatory filings only — press coverage is not a regulatory disclosure.

Filing span
70days

Time between earliest and latest filing

Not recorded for this incident

Discovery variance · Materiality delta · SEC filing delayno SEC 8-K in this cluster; needs two dated filings.

Regulatory clocksCalifornia CA 60-day OK · 48dFull clock table in Litigation Timeline

Incident timeline

Jan 13, 2023breach begins
Jan 14, 2023discovered
notification delay · 48 days
Mar 3, 2023first filing
watching for filings

Dashed segments are unestablished, not zero — they fill in as filings merge into this incident.

Member cascade — every filing about this breach

  1. FEB 3Leak sitelockbit_3 postfirst filing · attacker claim · unverifiedday 0
  2. MAR 3CA AGCA AG noticeno count stated+28d
  3. MAR 3IN AGIN AG noticestates nationwide total 2,349+28d
  4. APR 14Leak sitedispossessor postmost recent · attacker claim · unverified+70d
  5. Watching for additional filings — new sources merge into this incident automatically.

Roll-up facts — reconciled across members

Breach window
Jan 13, 2023Jan 14, 2023
CA AG
Discovered
Jan 14, 2023· 1d undetected
CA AG
Data types
Identity (basic)
CA AG

Each fact cites the member filing that establishes it; when filings conflict, every value shows with its source.

Count reconciliation

per-state reported counts

Nationwide (stated in a filing)

2,349

Sum of filed state slices

2· 0.1% of stated

100% of the stated total lives in states whose filings carry no count — the dashed share shrinks as filings land.

Evidence ladder — rungs this incident occupies

Leak-site claim2 members

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

No press coverage linked yet.

State AG / regulator filing2 members

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

No SEC filing or victim statement yet.

Merge provenance

Method
human
Confidence
1.00 · above the 0.85 auto-merge floor
Reviewed
operator-reviewed Aug 24, 2026 · at least one link edge was human-adjudicated
Audit
Every link edge records its method, confidence and model + prompt versions (100% is the strongest edge).

Merges are reversible — a wrong link can be detached with its audit trail intact. How merging works.

Filing velocity

Spread

70 days

Cadence

~1 / 23.3d

vs. multi-state median

8.8× slower

About this clustering

DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. This page states only what the linked filings agree on; each filing's own account stays on its own record, linked from the timeline below.

The weekly clock on records like this one

The Disclosure Clock is a weekly briefing on what landed in the disclosure record, and the gap between the criminals' post and the regulator's filing — measured on the whole record, with the method shown.

Weekly. Double opt-in, one-click unsubscribe, and the address goes nowhere else.