STURM, RUGER & COMPANY, INC.
bd_33d8926df2b3726e · schema v1 · pii pii-v1
Full breach record for STURM, RUGER & COMPANY, INC. →3 incidents on fileSturm, Ruger & Company, Inc. notified customers that its third-party payment vendor, Freestyle Solutions, experienced a data breach. Malware on the Freestyle server hosting ShopRuger.com captured customer payment card data, names, and addresses between September 2020 and February 2022. Ruger engaged Verizon for forensics, notified law enforcement, and offered 12 months of identity protection services. No evidence of improper use was found.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 18, 2020
Begins
Aug 2, 2022
Discovered
Aug 2, 2022
Filed
vs. sector median
8 wks faster
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Delaware State AGbd_1f4061fbb0cfdce22022-08-17 · +15dVerified
- California State AGbd_38f04b97485bb4182022-08-17 · +15dCandidate
- Maine State AGbd_9393cab4cdd552b62022-08-17 · +15dVerified
- Oregon State AGbd_ebaf2f767137b90a2022-08-17 · +15dVerified
Show 4 more filings ↓Show fewer ↑up to 17d gap
- Massachusetts State AGbd_2756ba599a1cd56c2022-08-18 · +16dVerified
- Indiana State AGbd_4fae1ff48d4333632022-08-18 · +16dVerified
- Washington State AGbd_ab208d75cc9435ea2022-08-18 · +16dVerified
- New Hampshire State AGbd_424fddae629065202022-08-19 · +17dVerified
Filing propagation · 9 filings · 8 states
View merged incident ↗Pattern: first filing Aug 2 (DE), last Aug 19 (NH) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.