HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Vermont Christmas Company
bd_1627e564dd024a85 · schema v1 · pii pii-v1
Full breach record for Vermont Christmas Company →Vermont Christmas Company notified consumers of a data breach involving its third-party e-commerce vendor, CommerceV3. Unauthorized access occurred between Nov 2021 and Dec 2022. Impacted data included names, billing addresses, emails, payment card numbers, CVVs, and expiration dates. CommerceV3 implemented additional security measures and notified law enforcement. Vermont Christmas Company is reviewing vendor procedures and notifying regulators.
Vermont clock✗ VT AG >45 bday14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_bbb64d7a974fdbe5California State AGfiled 2023-08-09Candidate
- bd_c56e39394fec7748New Hampshire State AGfiled 2023-08-09Verified
- bd_e2882215251a929bMaine State AGfiled 2023-08-09Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-09-vermont-christmas-company-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2023
- Raw hash
- 3b9fe065dc329e93c2ce5453b739f0a00a23a8a044fddcf259181c3b955e92fc
Reporting entity
- Name
- Vermont Christmas Companynorm: vermont christmas
- Domain
- vermontchristmasco.com
Victim entity
- Name
- Vermont Christmas Companynorm: vermont christmas
- Domain
- vermontchristmasco.com
Incident
- Discovered
- May 3, 2023
- Materiality determined
- —
- Notification sent
- Aug 9, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Vermont Attorney GeneralCommerceV3 notified law enforcement
- Third party
- via CommerceV3
- Initial access
- supply_chain
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.