HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Lee Valley Tools
bd_282e04dbb9abf769 · schema v1 · pii pii-v1
Full breach record for Lee Valley Tools →Lee Valley Tools, Ltd. disclosed that an unauthorized third party captured credit card information (number, expiration date, CVV) and personal data (name, address) from its website between October 8, 2024, and March 12, 2025. The company became aware of suspicious activity on March 12, 2025. The incident affected customers, including approximately 435 Rhode Island residents. The company engaged cybersecurity experts, notified law enforcement, and is offering 12 months of credit monitoring and identity restoration services.
California clockDiscovered Mar 12, 2025 → Notified Mar 28, 202516d ✓ CA 60-day OK28 days discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_66e2c81b16d18c74New Hampshire State AGfiled 2025-04-09Verified
- bd_9a4c3955773a1f40Vermont State AGfiled 2025-04-15(6d gap)Verified
- bd_fead9dabf61f395cIndiana State AGfiled 2025-04-15(6d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-601179
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 9, 2025
- Raw hash
- 52a8403998f25450eb5969acb4765914d9d1205a57398920f1bb022f459eebd4
Reporting entity
- Name
- Lee Valley Toolsnorm: lee valley tools
- Domain
- leevalley.com
Victim entity
- Name
- Lee Valley Toolsnorm: lee valley tools
- Domain
- leevalley.com
Incident
- Discovered
- Mar 12, 2025
- Materiality determined
- —
- Notification sent
- Mar 28, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 16d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 12, 2025→ Notified: Mar 28, 202516d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.