CSIDB logo
Incident

Mom's Meals

Incident posture

Attack window
Jan 2023
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-08-29 03:26

Linked entities

Victim
Mom's Meals
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2023
Discovered
Jul 2023
Disclosed
Aug 2023
Resolved
Pending

Summary

PurFoods, LLC experienced an external system breach that resulted in the acquisition of personal identifiers combined with financial account numbers and associated security credentials. The incident affected approximately 1.24 million individuals nationwide, including about 2,200 residents of Maine, and prompted written notification to those impacted. Identity theft protection services were offered through Kroll for periods of twelve and twenty‑four months, and no prior breach notifications had been issued within the preceding year.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

PurFoods, LLC, doing business as Mom's Meals, experienced a data breach that began on January 16, 2023, when an external system was compromised through hacking. The breach remained undetected until July 10, 2023, when the company's privacy officer identified the unauthorized access. According to the breach notification submitted to the Maine Attorney General's office, the compromised information included names or other personal identifiers combined with financial account numbers or credit/debit card numbers, along with the associated security codes, access codes, passwords, or PINs. The incident affected a total of 1,237,681 individuals nationwide, of whom 2,248 were residents of Maine.

On August 25, 2023, PurFoods, LLC issued written notifications to all affected individuals detailing the nature of the data that had been accessed. The notification informed recipients that their personal and financial data may have been exposed and provided instructions on how to monitor their accounts for suspicious activity. As part of the response, the company offered identity theft protection services to those impacted. The services were provided by Kroll and were available for either a twelve‑month or a twenty‑four‑month period, depending on the individual's preference. The offer of protection services was documented in the breach notification materials submitted to state authorities.

Because the number of Maine residents affected exceeded one thousand, PurFoods, LLC also notified the relevant consumer reporting agencies as required by state law. The breach notice indicated that there had been no prior breach notifications within the twelve months preceding this incident. The documentation submitted by Jane Sturtz, the company's privacy officer, included a copy of the notice sent to Maine residents and details of the identity theft protection offering.

Sources

Sources available to members: 1 source.

CSIDB