HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Bavaria Sausage
bd_1e26b8d1523f5ac6 · schema v1 · pii pii-v1
Full breach record for Bavaria Sausage →Bavaria Sausage, Inc. notified customers of a data security incident involving its online store (bavariasausage.com). The incident, occurring between April 6, 2024, and January 17, 2025, may have exposed payment card information, including names, emails, card numbers, expiration dates, and security codes. The company engaged forensic investigators, enhanced website security, and offered complimentary identity resolution and fraud assistance services.
Vermont clock✗ VT AG >45 bday47 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_8c204176c20f448eMontana State AGfiled 2025-03-03(1d gap)Candidate
- bd_8e09e118070e3ddcMaryland State AGfiled 2025-03-03(1d gap)Verified
- bd_a2e695d6c6447e90Indiana State AGfiled 2025-03-03(1d gap)Verified
- bd_bcdf3997d69929dbNew Hampshire State AGfiled 2025-03-03(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 3d gap
- bd_51b0c8458e17c904Maine State AGfiled 2025-03-07(3d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-04-bavaria-sausage-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 4, 2025
- Raw hash
- f4285ab1e91981029d5dc5833c785fb056dfb66c98f06d5a553529d9cd04c625
Reporting entity
- Name
- Bavaria Sausagenorm: bavaria sausage
- Domain
- bavariasausage.com
Victim entity
- Name
- Bavaria Sausagenorm: bavaria sausage
- Domain
- bavariasausage.com
Incident
- Discovered
- Apr 6, 2024
- Materiality determined
- Mar 3, 2025
- Notification sent
- Mar 3, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 47 weeks(332 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.