DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCustomer Data InvolvedTargetedIdentity (basic)Financial accountFinancial credentialsLowContained

Art of Tea

bd_0593c8221731370b · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 3, 2014

Filed

Dec 31, 2014

To disclose

28 days

Affected

5state residents only

Confidence

66%
Full breach record for Art of Tea2 incidents on file

Art of Tea notified the New Hampshire Attorney General of a cyberattack where criminals hacked its website to access payment card data (names, emails, billing addresses, credit card numbers, CVVs, expiration dates) for purchases made between Oct 16 and Nov 28, 2014. The incident affected 5 NH residents. Notices were mailed on Jan 5, 2015, offering credit monitoring.

Incident timeline

undetected · 48 days
discovery → filing · 28 days

Oct 16, 2014

Begins

Dec 3, 2014

Discovered

Dec 31, 2014

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.