DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountCredentialsMediumActive

SwimwearBoutique.com

bd_10303d66c20283dc · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 28, 2008

Filed

Apr 16, 2008

To disclose

19 days

Affected

312state residents only

Linked

2 filings

Confidence

64%
Full breach record for SwimwearBoutique.com

SwimwearBoutique.com notified the NH Attorney General of a criminal intrusion discovered on March 28, 2008. Unauthorized access occurred between March 26 and 28, 2008, affecting approximately 312 New Hampshire residents. Data accessed included names, addresses, credit card numbers, and passwords. The company engaged the Secret Service and McAfee, implemented security measures, and offered one year of identity protection services. Notification letters were scheduled for April 23, 2008.

Incident timeline

undetected · 2 days
discovery → filing · 19 days

Mar 26, 2008

Begins

Mar 28, 2008

Discovered

Apr 16, 2008

Filed

vs. sector median

5 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGApr 16 · first · this page

Pattern: first filing Apr 16 (NH), last Apr 22 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.