HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumActive
SwimwearBoutique.com
bd_10303d66c20283dc · schema v1 · pii pii-v1
Full breach record for SwimwearBoutique.com →SwimwearBoutique.com notified the NH Attorney General of a criminal intrusion discovered on March 28, 2008. Unauthorized access occurred between March 26 and 28, 2008, affecting approximately 312 New Hampshire residents. Data accessed included names, addresses, credit card numbers, and passwords. The company engaged the Secret Service and McAfee, implemented security measures, and offered one year of identity protection services. Notification letters were scheduled for April 23, 2008.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed312 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/swimwear-boutique-20080416.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 16, 2008
- Raw hash
- 914270e5f30fea8594dafd3442963a67b0cccc8a371163fa2cc85ed7f9ccc62f
Reporting entity
- Name
- SwimwearBoutique.comnorm: swimwearboutiquecom
Victim entity
- Name
- SwimwearBoutique.comnorm: swimwearboutiquecom
Incident
- Discovered
- Mar 28, 2008
- Materiality determined
- —
- Notification sent
- Apr 23, 2008
- Affected individuals
- 312
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 days(19 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.