HackingCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
MarketPlace: Handwork of India
bd_0b6401102608e455 · schema v1 · pii pii-v1
Full breach record for MarketPlace: Handwork of India →MarketPlace Handwork of India notified consumers of a data breach affecting its third-party e-commerce platform, CommerceV3. Unauthorized access occurred between Nov 2021 and Dec 2022. Potentially impacted data included names, emails, billing addresses, and payment card details (number, expiration, CVV). No evidence of misuse was found. Affected individuals were offered 12 months of credit monitoring.
Vermont clock✗ VT AG >45 bday14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_d42937317e38b72aOregon State AGfiled 2023-09-11Candidate
- bd_fb18a94c3350429bMaine State AGfiled 2023-09-11Verified
- bd_92faa74eccb78f02California State AGfiled 2023-09-12(1d gap)Verified
- bd_02484d172a074742New Hampshire State AGfiled 2023-09-18(7d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-09-11-marketplace-handwork-india-commercev3-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2023
- Raw hash
- 209a80fcd27d98b9cd17ca7a3def8e888199b0abf740a7614c6ea939ee71f97f
Reporting entity
- Name
- MarketPlace: Handwork of Indianorm: marketplace handwork of india
Victim entity
- Name
- MarketPlace: Handwork of Indianorm: marketplace handwork of india
Incident
- Discovered
- Jun 6, 2023
- Materiality determined
- —
- Notification sent
- Sep 11, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Third party
- via CommerceV3
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.