HackingSupply Chain (3P Vendor)Customer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
Roots & Harvest Direct LLC
bd_2ce5ac206fc61009 · schema v1 · pii pii-v1
Full breach record for Roots & Harvest Direct LLC →Roots & Harvest Direct LLC notified the NH Attorney General of a third-party vendor breach involving CommerceV3. Unauthorized access to CommerceV3's systems occurred between Nov 24, 2021 and Dec 14, 2022. Cardholder data for 27 NH residents was potentially accessed. Notification letters were mailed on July 13, 2023.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_50caf27259718c06Montana State AGfiled 2023-07-13Candidate
- bd_cbec415dc44f19abMaine State AGfiled 2023-07-14(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/roots-harvest-direct-20230713.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 13, 2023
- Raw hash
- 3bc8dca7f6cecff903769aee8ae8141c3beaeaaf6de6545afd0b7b5821dfeff7
Reporting entity
- Name
- Roots & Harvest Direct LLCnorm: roots harvest direct
Victim entity
- Name
- Roots & Harvest Direct LLCnorm: roots harvest direct
Incident
- Discovered
- May 3, 2023
- Materiality determined
- —
- Notification sent
- Jul 13, 2023
- Affected individuals
- 27
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Third party
- via CommerceV3
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.