HackingRetail & ConsumerRetailAbuse Of FunctionalityCapture App DataData MishandlingData ExfiltratedCustomer Data InvolvedTargetedDelayed DiscoveryPIIPCIFINANCIALLowContained
5.11, Inc
bd_2c151da7f96a559b · schema v1 · pii pii-v1
Full breach record for 5.11, Inc →5.11, Inc. (511tactical.com) identified unauthorized activity on its online store in August 2024. A forensic investigation determined that between July 12, 2024 and August 22, 2024, an external actor may have accessed customer payment card data including names, email addresses, card numbers, expiration dates, and security codes. 127 Maine residents were among the approximately 27,742 individuals potentially affected. Consumer notifications were sent October 3, 2024.
Maine clockDiscovered Sep 12, 2024 → Filed with AG Oct 5, 202423d ✓ ME AG ≤30d23 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_26c0478bb272bd4eOregon State AGfiled 2024-10-05Verified
- bd_6899f0e1993e67d5Washington State AGfiled 2024-10-05Verified
- bd_c2a90fe02a449cc7California State AGfiled 2024-10-05Verified
- bd_4f9fc1d533ca6b72Indiana State AGfiled 2024-10-04(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_bd3adc8660ef9facMontana State AGfiled 2024-10-04(1d gap)Candidate
- bd_d4546feba8b6348eVermont State AGfiled 2024-10-04(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/941df45f-c335-4c8c-8918-7c01c1d0014a.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 5, 2024
- Raw hash
- e6820ba0defce95f6ce1e4127c13010390250d5b1bac33cbf2933180d7572d93
Reporting entity
- Name
- 5.11, Incnorm: 511
- Domain
- 511tactical.com
- Industry
- Other Commercial
Victim entity
- Name
- 5.11, Incnorm: 511
- Domain
- 511tactical.com
- Industry
- Other Commercial
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Sep 12, 2024
- Materiality determined
- —
- Notification sent
- Oct 3, 2024
- Affected individuals
- 127
- Data types
- PIIPCIFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1185 Browser Session HijackingT1041 Exfiltration Over C2 ChannelT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 23d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Sep 12, 2024→ Filed with AG: Oct 5, 202423d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.