MalwareRansomwareData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
STURM, RUGER & COMPANY, INC.
bd_33d8926df2b3726e · schema v1 · pii pii-v1
Full breach record for STURM, RUGER & COMPANY, INC. →Sturm, Ruger & Company, Inc. notified customers that its third-party payment vendor, Freestyle Solutions, experienced a data breach. Malware on the Freestyle server hosting ShopRuger.com captured customer payment card data, names, and addresses between September 2020 and February 2022. Ruger engaged Verizon for forensics, notified law enforcement, and offered 12 months of identity protection services. No evidence of improper use was found.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_38f04b97485bb418California State AGfiled 2022-08-17(15d gap)Candidate
- bd_9393cab4cdd552b6Maine State AGfiled 2022-08-17(15d gap)Verified
- bd_ebaf2f767137b90aOregon State AGfiled 2022-08-17(15d gap)Verified
- bd_ab208d75cc9435eaWashington State AGfiled 2022-08-18(16d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 17d gap
- bd_424fddae62906520New Hampshire State AGfiled 2022-08-19(17d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/08/Ruger-Template-Individual-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 2, 2022
- Raw hash
- 1bd3ce10478110282ddda5e9065cbc89841d2341d433376bc36f44df4c4b0e78
Reporting entity
- Name
- STURM, RUGER & COMPANY, INC.norm: sturm ruger
- Domain
- shopruger.com
Victim entity
- Name
- STURM, RUGER & COMPANY, INC.norm: sturm ruger
- Domain
- shopruger.com
Incident
- Discovered
- Aug 2, 2022
- Materiality determined
- —
- Notification sent
- Aug 18, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement authorities
- Third party
- via Freestyle Solutions
- Initial access
- external_remote_services
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.