DisclosureLens
HackingRetail & ConsumerRetailCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Financial accountFinancial credentialsLowResolved

Savory Spice, Inc

bd_0c7c66767f2a2989 · schema v1 · pii pii-v1

Severity

Low

Discovered

Oct 8, 2020

Filed

Jul 23, 2021

To disclose

41 weeks

Affected

Not disclosed

Linked

8 filings

Confidence

65%
Full breach record for Savory Spice, Inc

Savory Spice disclosed that an unauthorized third-party attacked its computer network, gaining access to customer purchase information between April 5, 2018, and March 27, 2021. The company learned of the incident on October 8, 2020, and concluded its investigation on July 14, 2021. Affected data may include names, credit/debit card numbers, expiration dates, and security codes. Savory Spice engaged third-party forensics and implemented new security measures.

Incident timeline

undetected · 917 days
discovery → filing · 41 weeks / 288 days

Apr 5, 2018

Begins

Oct 8, 2020

Discovered

Jul 23, 2021

Filed

vs. sector median

+34 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 3d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗
Washington State AGJul 23 · first
Indiana State AGJul 23 · first
Massachusetts State AGJul 23 · first
Maine State AGJul 23 · first
Oregon State AGJul 23 · first
Montana State AGJul 23 · first
California State AGJul 23 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.