DisclosureLens
MalwareRetail & ConsumerRetailRansomwareVulnerability ExploitData ExfiltratedCustomer Data InvolvedMulti-Stage ChainPCIFinancial accountIdentity (basic)LowContained

AeroGrow International Inc

bd_15c9ef680eaa947d · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 10, 2015

Filed

Jul 9, 2015

To disclose

29 days

Affected

Not disclosed

Linked

4 filings

Confidence

64%
Full breach record for AeroGrow International Inc2 incidents on file

AeroGrow International, Inc. disclosed a data breach affecting customer payment card information. Malware infiltrated online servers between October 15, 2014, and June 10, 2015, potentially capturing names, addresses, and credit card details. The company eradicated the malware, alerted law enforcement, and offered identity protection services to affected customers.

California clockDiscovered Jun 10, 2015Notified Jul 10, 201530d CA 60-day OK29 days discovery → filing

Incident timeline

undetected · 238 days
discovery → filing · 29 days

Oct 15, 2014

Begins

Jun 10, 2015

Discovered

Jul 9, 2015

Filed

vs. sector median

3 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 2 states

View merged incident ↗
California State AGJun 3 · first
California State AG+36d · this page

Pattern: first filing Jun 3 (NH), last Jul 9 (CA) — a 36-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.