DisclosureLens
HackingRetail & ConsumerRetailSkimmerCapture Stored DataSupply Chain (3P Vendor)Delayed DiscoveryCustomer Data InvolvedIdentity (basic)PCIFinancial accountMediumContained

Pennsylvania General Store

bd_0a85d081d999d2b5 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 6, 2023

Filed

Oct 27, 2023

To disclose

20 weeks

Affected · nationwide

19,45465 in this filing

Linked

3 filings

Confidence

65%
Full breach record for Pennsylvania General Store2 incidents on file

Pennsylvania General Store, a retail entity, reported a data breach affecting 19,454 individuals. The breach was caused by a skimming attack on its third-party e-commerce vendor, CommerceV3, which compromised customer names and payment card information. The incident occurred on November 24, 2021, but was not discovered until June 6, 2023. Affected individuals were notified on September 15, 2023.

Maine clockDiscovered Jun 6, 2023Filed with AG Oct 27, 2023143d ME AG >90d20 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 559 days
discovery → filing · 20 weeks / 143 days

Nov 24, 2021

Begins

Jun 6, 2023

Discovered

Oct 27, 2023

Filed

vs. sector median

+13 wks slower

This filing is one of 3 about the same incident.View merged incident
Part of CommerceV3 supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Indiana State AGSep 15 · first
Maine State AG+42d · this page

Pattern: first filing Sep 15 (IN), last Oct 27 (ME) — a 42-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.