DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Financial accountLowContained

SeneGence

bd_00a9299bc286074a · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 25, 2024

Filed

Nov 22, 2024

To disclose

17 weeks

Affected

11state residents only

Linked

5 filings

Confidence

66%
Full breach record for SeneGence

SGII, Inc. dba SeneGence notified Montana consumers of a cybersecurity incident occurring July 22, 2024, where an unknown threat actor inserted a false checkout page into its e-commerce platform. The incident exposed names, addresses, phone numbers, and credit card information. SeneGence discovered the incident on July 25, 2024, and remediated it by July 27, 2024. Notices were sent on November 22, 2024, offering 24 months of Experian IdentityWorks.

Incident timeline

undetected · 3 days
discovery → filing · 17 weeks / 120 days

Jul 22, 2024

Begins

Jul 25, 2024

Discovered

Nov 22, 2024

Filed

vs. sector median

+10 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Vermont State AGNov 21 · first
Montana State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.