DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsTargetedIdentity (basic)Financial accountFinancial credentialsLowContained

Morris 4x4

bd_36da16cf7096bf24 · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 4, 2021

Filed

Mar 5, 2021

To disclose

29 days

Affected

4state residents only

Linked

5 filings

Confidence

65%
Full breach record for Morris 4x4

Morris 4x4 notified customers that malicious code placed on its web store between Oct 27-29, 2020, may have captured personal and credit card information (including CVV). The company determined on Feb 4, 2021, that specific customers were affected. Morris 4x4 worked with its hosting provider to remove the code and alerted credit card companies.

Incident timeline

undetected · 100 days
discovery → filing · 29 days

Oct 27, 2020

Begins

Feb 4, 2021

Discovered

Mar 5, 2021

Filed

vs. sector median

3 wks faster

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Indiana State AGMar 5 · first
Maine State AGMar 5 · first
Montana State AGMar 5 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.