HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALSLowContained
SelectBlinds
bd_1af605e003eeaade · schema v1 · pii pii-v1
Full breach record for SelectBlinds →SelectBlinds notified consumers of a data breach where malware was embedded on its website starting Jan 7, 2024, allowing data scraping of checkout transactions. The incident was discovered on Sept 28, 2024. Compromised data included names, addresses, phone numbers, and payment card details (number, expiration, CVV). SelectBlinds contained the incident, removed malware, and locked user accounts.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_1923f9007672926fMaine State AGfiled 2024-10-31Verified
- bd_302d1ff6caa823bcDelaware State AGfiled 2024-10-31Candidate
- bd_3d0c0642d4dc639aMontana State AGfiled 2024-10-31Verified
- bd_41a17bd100035b7fIndiana State AGfiled 2024-10-31Verified
Show 6 more filings ↓Show fewer ↑up to 24d gap
- bd_7dfc75746b157d31New Hampshire State AGfiled 2024-10-31Verified
- bd_7ed9e87de0e792e1California State AGfiled 2024-10-31Verified
- bd_dd07d60af013eeadOregon State AGfiled 2024-10-31Verified
- bd_e041a012af34a2d7Washington State AGfiled 2024-10-31Verified
- bd_8c0eda7f606a2408Vermont State AGfiled 2024-10-29(2d gap)Candidate
- bd_8a9d4c7ca3c46cc5Delaware State AGfiled 2024-10-07(24d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-10-31-selectblinds-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 31, 2024
- Raw hash
- bbed66ab3d742e3fc9c4dca792369551c7706d9c74151ebe57f497aa30b4afbf
Reporting entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Victim entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Incident
- Discovered
- Sep 28, 2024
- Materiality determined
- —
- Notification sent
- Oct 31, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.