HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
Blundstone (U.S.A.) Inc.
bd_2676fe0caf8e9561 · schema v1 · pii pii-v1
Full breach record for Blundstone (U.S.A.) Inc. →Blundstone (U.S.A.) Inc. notified the NH AG of a security incident affecting 44 NH residents. An unauthorized third party exploited a vulnerability in the Adobe Commerce platform between July 7 and August 14, 2024, to install malicious code that duplicated the checkout page and collected contact and payment information. Blundstone discovered the incident on August 15, 2024, engaged forensic investigators and legal counsel, removed the malicious code, and applied security patches.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_4d7eaaf90dd137d9Montana State AGfiled 2024-09-14(1d gap)Candidate
- bd_f45176f5ded33fe9Indiana State AGfiled 2024-09-14(1d gap)Verified
- bd_714ab241355383f2California State AGfiled 2024-09-20(7d gap)Verified
- bd_7a9af778c88c7215Maine State AGfiled 2024-09-20(7d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_d52977427ecd9344Vermont State AGfiled 2024-09-20(7d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/blundstone-usa-20240913.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 13, 2024
- Raw hash
- 1ab4c04de1e292bd737b51e3da34e31cde48f3ac6dbd8e6a4ef2d8bea4c9872a
Reporting entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
Victim entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
Incident
- Discovered
- Aug 15, 2024
- Materiality determined
- —
- Notification sent
- Sep 14, 2024
- Affected individuals
- 44
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.