Creedmoor Sports, Inc.
bd_167334df96174e9c · schema v1 · pii pii-v1
Full breach record for Creedmoor Sports, Inc. →3 incidents on fileCreedmoor Sports, Inc. notified the WA AG of a data security incident involving its third-party e-commerce platform, CommerceV3. Unauthorized access occurred between Nov 24, 2021 and Dec 14, 2022. Creedmoor was notified on June 6, 2023. Cardholder data (names, emails, billing addresses, card numbers, CVVs) was potentially accessed. 518 WA residents affected. Notifications sent July 21, 2023, including credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2021
Begins
Jun 6, 2023
Discovered
Jul 21, 2023
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_8249e93e5f00a74c2023-07-21Verified
- Indiana State AGbd_ab9f8ee8b2447eff2023-07-21Verified
- Oregon State AGbd_b0e68c14af9337772023-07-21Verified
- Massachusetts State AGbd_98f1889f12aa4ca12023-07-28 · +7dVerified
Show 1 more filing ↓Show fewer ↑up to 10d gap
- New Hampshire State AGbd_1d3b27e3486192b72023-07-31 · +10dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jul 21 (ME), last Jul 31 (NH) — a 10-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.