Bombas
bd_032c860efe4a2ff3 · schema v1 · pii pii-v1
Full breach record for Bombas →4 incidents on fileBombas LLC notified Montana residents of a data breach involving malicious code on its e-commerce platform. The code, present from Nov 11, 2016 to Feb 16, 2017, potentially scraped customer names, addresses, and payment card data. Bombas added a security feature in Feb 2017 to stop the code and offered two years of free identity monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 11, 2016
Begins
Nov 11, 2016
Discovered
Jun 3, 2020
Filed
vs. sector median
+178 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_2e0f55b86f1170a32020-06-03Verified
- Oregon State AGbd_2f92b42d2848b3ab2020-06-03Verified
- California State AGbd_9101cc153fd11ef12020-06-03Verified
- Indiana State AGbd_9b29684e29b93fe12020-06-03Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- Washington State AGbd_f50804e00f8304562020-06-03Verified
- Massachusetts State AGbd_43c63091f0426d8f2020-06-04 · +1dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.