HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALSLowContained
SelectBlinds
bd_302d1ff6caa823bc · schema v1 · pii pii-v1
Full breach record for SelectBlinds →SelectBlinds, an online retailer of custom window coverings, disclosed a data breach occurring on or about January 7, 2024, discovered on September 28, 2024. An unauthorized third party embedded malware on the SelectBlinds website to scrape sales transaction data from the checkout page. Affected data included names, emails, shipping/billing addresses, phone numbers, and payment card information (number, expiration, CVV). The incident was contained, malware eradicated, and notifications sent on October 31, 2024, to affected individuals, including 815 Rhode Island residents.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_1923f9007672926fMaine State AGfiled 2024-10-31Verified
- bd_1af605e003eeaadeVermont State AGfiled 2024-10-31Verified
- bd_3d0c0642d4dc639aMontana State AGfiled 2024-10-31Verified
- bd_41a17bd100035b7fIndiana State AGfiled 2024-10-31Verified
Show 6 more filings ↓Show fewer ↑up to 24d gap
- bd_7dfc75746b157d31New Hampshire State AGfiled 2024-10-31Verified
- bd_7ed9e87de0e792e1California State AGfiled 2024-10-31Verified
- bd_dd07d60af013eeadOregon State AGfiled 2024-10-31Verified
- bd_e041a012af34a2d7Washington State AGfiled 2024-10-31Verified
- bd_8c0eda7f606a2408Vermont State AGfiled 2024-10-29(2d gap)Candidate
- bd_8a9d4c7ca3c46cc5Delaware State AGfiled 2024-10-07(24d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/11/Notification-Samples.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 31, 2024
- Raw hash
- 820dae4576707eb3a5ef0bd884413e990ec14c3963cf86da89cfcd8b16c93343
Reporting entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Victim entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Incident
- Discovered
- Sep 28, 2024
- Materiality determined
- —
- Notification sent
- Oct 31, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.