HackingData ExfiltratedData PublishedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The Computer Merchant, Ltd.
bd_2b56afa7cd461874 · schema v1 · pii pii-v1
Full breach record for The Computer Merchant, Ltd. →The Computer Merchant, Ltd. experienced a cyberattack in July 2024. In January 2025, the company became aware that data from the incident had been made publicly available. The breach involved names and Social Security numbers. The company secured its systems, engaged a data-review firm, and is offering identity-theft protection services.
California clockDiscovered Jan 1, 2025 → Notified Aug 19, 2025230d ✗ CA 60-day late33 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_6d00600f90f10c7cLeak Siteplayfiled 2024-07-15(402d gap)Verified
- bd_29f325ee9c9bd6f7Leak Siteplayfiled 2024-06-28(419d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_08dc2d6569d82510New Hampshire State AGfiled 2025-08-21Verified
- bd_59bcb7c5698db8fdVermont State AGfiled 2025-08-19(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-607506
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 21, 2025
- Raw hash
- a9c7c8c70fb920e55c48f5c17b8bc162b648c51d6e292c3e0ae5bdaf739f347c
Reporting entity
- Name
- The Computer Merchant, Ltd.norm: the computer merchant
- Domain
- itstaffing.com
Victim entity
- Name
- The Computer Merchant, Ltd.norm: the computer merchant
- Domain
- itstaffing.com
Incident
- Discovered
- Jan 1, 2025
- Materiality determined
- —
- Notification sent
- Aug 19, 2025
- Affected individuals
- 433
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 33 weeks(232 days from discovery to filing)
- Compliance flags
- CA 60-day late · 230dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 1, 2025→ Notified: Aug 19, 2025230d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.