MalwareRansomwareData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
AeroGrow International Inc
bd_15c9ef680eaa947d · schema v1 · pii pii-v1
Full breach record for AeroGrow International Inc →AeroGrow International, Inc. reported a cybersecurity incident involving malicious software (malware) infiltrating its online servers hosted by a third-party provider. The breach affected customer data, including names, addresses, and payment card details (account number, expiration, CVV), collected between May 13, 2015, and June 10, 2015. The company eradicated the malware, alerted law enforcement, and offered free identity protection services via Experian. This filing serves as a supplemental notification to a prior notice.
California clockDiscovered Jun 10, 2015 → Notified Jul 10, 201530d ✓ CA 60-day OK29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_783164df3d6bebcaCalifornia State AGfiled 2015-06-03(36d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-56988
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 9, 2015
- Raw hash
- 3931cfa5d914457135fd03a7cf929d361f92d5900baf2f47b300f2e850c12fda
Reporting entity
- Name
- AeroGrow International Incnorm: aerogrow international
Victim entity
- Name
- AeroGrow International Incnorm: aerogrow international
Incident
- Discovered
- Jun 10, 2015
- Materiality determined
- —
- Notification sent
- Jul 10, 2015
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 10, 2015→ Notified: Jul 10, 201530d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.