Roots & Harvest Direct LLC
bd_2ce5ac206fc61009 · schema v1 · pii pii-v1
Full breach record for Roots & Harvest Direct LLC →Roots & Harvest Direct LLC notified the NH Attorney General of a third-party vendor breach involving CommerceV3. Unauthorized access to CommerceV3's systems occurred between Nov 24, 2021 and Dec 14, 2022. Cardholder data for 27 NH residents was potentially accessed. Notification letters were mailed on July 13, 2023.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2021
Begins
May 3, 2023
Discovered
Jul 13, 2023
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_0254195321496ea82023-07-13Verified
- Montana State AGbd_50caf27259718c062023-07-13Candidate
- Maine State AGbd_cbec415dc44f19ab2023-07-14 · +1dVerified
- Indiana State AGbd_7a3b00926d3f02aa2023-07-06 · +7dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 6 (IN), last Jul 14 (ME) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.