DisclosureLens
MalwareRetail & ConsumerRetailData ExfiltratedCustomer Data InvolvedPCIFinancial accountIdentity (basic)LowContained

Backcountry Gear

bd_24d8c04fec0ef50d · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 23, 2014

Filed

Jul 28, 2014

To disclose

5 days

Affected

Not disclosed

Linked

2 filings

Confidence

64%
Full breach record for Backcountry Gear3 incidents on file

Backcountry Gear discovered malware on its server on July 23, 2014, which had been installed on April 27, 2014. The malware compromised customer payment card information (names, addresses, purchase info, card numbers) for orders placed between April 27 and July 17, 2014. The company contained the malware, reported the incident to law enforcement, its merchant bank, and credit bureaus, and implemented security measures.

California clockDiscovered Jul 23, 2014Notified Jul 28, 20145d CA 60-day OK5 days discovery → filing

Incident timeline

undetected · 87 days
discovery → filing · 5 days

Apr 27, 2014

Begins

Jul 23, 2014

Discovered

Jul 28, 2014

Filed

vs. sector median

7 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
California State AGJul 28 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.