The Howland-Hughes Company
bd_203def68cc8e0c00 · schema v1 · pii pii-v1
Full breach record for The Howland-Hughes Company →The Howland-Hughes Company (dba The Connecticut Store) notified the NH AG of unauthorized access to its shopping cart software. An exploited flaw allowed attackers to upload malicious code between April 9 and Nov 26, 2012. Discovered Dec 9, 2012. 6 NH residents affected; credit card and PII compromised. Malicious code removed; audits ongoing.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 9, 2012
Begins
Dec 9, 2012
Discovered
Jan 30, 2013
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_4924f781d40160422013-02-04 · +5dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Jan 30 (NH), last Feb 4 (MA) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.