MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Ballistic Products, Inc.
bd_0a9e5025b2e7d8d8 · schema v1 · pii pii-v1
Full breach record for Ballistic Products, Inc. →Ballistic Products, Inc. disclosed a data breach involving a third-party e-commerce vendor's servers. Malware captured payment card data, billing addresses, and personal information for customers who made purchases between September 18, 2020, and February 3, 2022. The company notified affected individuals, offered credit monitoring and identity theft protection, and reported the incident to law enforcement.
California clockDiscovered Feb 3, 2022 → Notified Sep 1, 2022210d ✗ CA 60-day late31 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_aaecbad195251dcdMaine State AGfiled 2022-09-13(4d gap)Verified
- bd_c6b9c657e9d72d47Oregon State AGfiled 2022-09-13(4d gap)Verified
- bd_cc0ec26377c09de6Washington State AGfiled 2022-09-03(6d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-557104
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 9, 2022
- Raw hash
- e6186802df3b5546cf083b3e3542f4d40a5cec58eb804fbe304f5195bf8b430a
Reporting entity
- Name
- Ballistic Products, Inc.norm: ballistic products
Victim entity
- Name
- Ballistic Products, Inc.norm: ballistic products
Incident
- Discovered
- Feb 3, 2022
- Materiality determined
- —
- Notification sent
- Sep 1, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported to law enforcement
- Initial access
- supply_chain
Compliance
- Time to disclose
- 31 weeks(218 days from discovery to filing)
- Compliance flags
- CA 60-day late · 210d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 3, 2022→ Notified: Sep 1, 2022210d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.