Pennsylvania General Store
bd_0a85d081d999d2b5 · schema v1 · pii pii-v1
Full breach record for Pennsylvania General Store →2 incidents on filePennsylvania General Store, a retail entity, reported a data breach affecting 19,454 individuals. The breach was caused by a skimming attack on its third-party e-commerce vendor, CommerceV3, which compromised customer names and payment card information. The incident occurred on November 24, 2021, but was not discovered until June 6, 2023. Affected individuals were notified on September 15, 2023.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2021
Begins
Jun 6, 2023
Discovered
Oct 27, 2023
Filed
vs. sector median
+13 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- California State AGbd_4c4e49ad2408dba32023-10-27Verified
- Indiana State AGbd_229a53d6a2ad0b652023-09-15 · +42dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Sep 15 (IN), last Oct 27 (ME) — a 42-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.