International Coffee & Tea, LLC, the parent company of The Coffee Bean & Tea Leaf, recently experienced a significant data breach that compromised sensitive consumer information. The breach was first discovered on June 6, 2024, when the company noticed suspicious activity in its computer environment. Following an investigation with third-party cybersecurity specialists, it was determined that an unauthorized actor gained access to certain systems on multiple occasions.
The breach occurred in three distinct timeframes: April 5 to May 29, 2024, June 6, 2024, and August 28 to August 29, 2024. During these incidents, unauthorized access was gained to company systems and limited email accounts. This unauthorized access resulted in the exposure of sensitive consumer data.
The breach affected a total of 53,901 individuals in the United States. Among those impacted, 11 were residents of Maine, and 110 were residents of Massachusetts.
The types of information exposed included:
The breach was disclosed to the California Attorney General on December 20, 2024, the Maine Attorney General on December 24, 2024, and the Massachusetts Attorney General on December 20, 2024.
The breach was severe due to the highly sensitive nature of the information exposed. The compromised data, such as Social Security numbers and financial account details, could be used for identity theft or financial fraud, making it critical for affected individuals to take immediate protective measures.
In response to the breach, International Coffee & Tea took several steps to mitigate the damage and prevent future incidents. Upon discovering the suspicious activity, the company launched an investigation with the help of third-party cybersecurity specialists and internal teams. They worked to identify the scope of the breach and determine which individuals were affected.
The company has since notified federal law enforcement and relevant state regulators about the incident. Additionally, they are offering 12 months of complimentary credit monitoring and identity restoration services through Equifax to individuals whose personal information was potentially affected.
To further protect consumer data, the company is implementing enhanced employee training and additional security measures to strengthen its systems against future attacks.
If you have been notified that your information was part of this breach, it is essential to act quickly to protect yourself.
Here are the steps you should take: