DisclosureLens
HackingTechnologyInformationCustomer Data InvolvedIdentity (basic)Government IDMediumContained

ACTIVEOutdoors

bd_0043817ab2e52546 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 22, 2016

Filed

Sep 19, 2016

To disclose

28 days

Affected

Not disclosed

Linked

7 filings

Confidence

66%
Full breach record for ACTIVEOutdoors2 incidents on file

ACTIVEOutdoors disclosed unauthorized access to its online hunting and fishing licensing applications in Idaho, Oregon, and Washington. The company became aware of the incident on August 22, 2016. Affected data included names, addresses, dates of birth, driver's license numbers, and Social Security numbers for accounts created prior to 2006/2007. No financial data was involved. The company engaged a cybersecurity firm, coordinated with state agencies, and offered two years of identity protection services to affected individuals.

California clockDiscovered Aug 22, 2016Notified Sep 19, 201628d CA 60-day OK28 days discovery → filing

Incident timeline

discovery → filing · 28 days

Aug 22, 2016

Discovered

Sep 19, 2016

Filed

vs. sector median

15 wks faster

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 28d gap

Filing propagation · 7 filings · 7 states

View merged incident ↗

Pattern: first filing Aug 22 (HI), last Sep 21 (SC) — a 30-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.