Bombas
bd_2e0f55b86f1170a3 · schema v1 · pii pii-v1
Full breach record for Bombas →4 incidents on fileBombas, LLC notified the NH AG of a security incident where malicious code on its Shopify e-commerce platform may have scraped customer data (names, addresses, payment card info) between Nov 11, 2016 and Feb 16, 2017. Approximately 680 NH residents affected. Bombas engaged Stroz Friedberg for investigation and offered 2 years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 11, 2016
Begins
Nov 11, 2019
Discovered
Jun 3, 2020
Filed
vs. sector median
+22 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Montana State AGbd_032c860efe4a2ff32020-06-03Candidate
- Oregon State AGbd_2f92b42d2848b3ab2020-06-03Verified
- California State AGbd_9101cc153fd11ef12020-06-03Verified
- Indiana State AGbd_9b29684e29b93fe12020-06-03Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- Washington State AGbd_f50804e00f8304562020-06-03Verified
- Massachusetts State AGbd_43c63091f0426d8f2020-06-04 · +1dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.