DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsTargetedData ExfiltratedPIIFinancial accountFinancial credentialsLowContained

SmokingPipes.com

bd_28736a1b2baa6866 · schema v1 · pii pii-v1

Severity

Low

Discovered

Nov 18, 2019

Filed

Dec 16, 2019

To disclose

28 days

Affected

1state residents only

Confidence

67%
Full breach record for SmokingPipes.com

SmokingPipes.com disclosed a data privacy incident discovered on November 18, 2019, where malicious code on the checkout page captured customer payment card information (name, card number, expiration, CVV). The company removed the code, launched an investigation, and reported the incident to credit card companies and state regulators. No actual misuse was known.

Incident timeline

discovery → filing · 28 days

Nov 18, 2019

Discovered

Dec 16, 2019

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.