HackingVulnerability ExploitCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Kiefer Aquatics
bd_3765e3d478004faf · schema v1 · pii pii-v1
Full breach record for Kiefer Aquatics →Kiefer Aquatics disclosed that an unknown actor accessed or could have accessed credit/debit card information of customers who made purchases on kiefer.com, thelifeguardstore.com, and allamericanswim.com between February 6, 2022, and June 28, 2022. The company became aware of suspicious online activity on July 21, 2022. The incident involved unauthorized access to e-commerce platforms. The company engaged forensic specialists, contained the access, and enhanced security procedures. Address information may also have been impacted.
California clockDiscovered Jul 21, 2022 → Notified Feb 22, 2023216d ✗ CA 60-day late33 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0544f2165bb6ad72Maine State AGfiled 2023-03-09Candidate
- bd_4b1b03d7a4b29f56Montana State AGfiled 2023-03-09Verified by operator
- bd_4f0985924663bfabVermont State AGfiled 2023-03-09Verified
- bd_56c0a8989af34ed8New Hampshire State AGfiled 2023-03-13(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564129
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 9, 2023
- Raw hash
- 02f4bbab5d6285b191fab663ba7fbe94eed20c23b78b6071ead8e7f0e47e43d0
Reporting entity
- Name
- Kiefer Aquaticsnorm: kiefer aquatics
- Domain
- kiefer.com
Victim entity
- Name
- Kiefer Aquaticsnorm: kiefer aquatics
- Domain
- kiefer.com
Incident
- Discovered
- Jul 21, 2022
- Materiality determined
- —
- Notification sent
- Feb 22, 2023
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 33 weeks(231 days from discovery to filing)
- Compliance flags
- CA 60-day late · 216d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 21, 2022→ Notified: Feb 22, 2023216d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.