HackingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Rainier Arms
bd_3936a805d43005a0 · schema v1 · pii pii-v1
Full breach record for Rainier Arms →Rainier Arms, a commercial entity based in Auburn, WA, reported an external system breach (hacking) occurring between June 1, 2021, and January 19, 2022. The incident affected 46,319 individuals, including 176 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). The breach was discovered on May 31, 2022, and written notifications were sent to consumers on June 2, 2022. No identity theft protection services were offered.
Maine clockDiscovered May 31, 2022 → Filed with AG Jun 2, 20222d ✓ ME AG ≤30d2 days discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_4e052c36c3c75137Oregon State AGfiled 2022-06-02Candidate
- bd_6dd37b7937da7256Montana State AGfiled 2022-06-02Verified by operator
- bd_7a232b15ca1c34f3Washington State AGfiled 2022-06-02Verified
- bd_c12823e14182c7abCalifornia State AGfiled 2022-06-02Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/caa1d52d-c653-4728-be2e-ba5432c57a58.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 2, 2022
- Raw hash
- 8425dcfaf3c41e0c2493b782cf957d2109c02c3d91a3f45d49d47c59e7e5aac2
Reporting entity
- Name
- Rainier Armsnorm: rainier arms
- Domain
- rainierarms.com
Victim entity
- Name
- Rainier Armsnorm: rainier arms
- Domain
- rainierarms.com
Incident
- Discovered
- May 31, 2022
- Materiality determined
- —
- Notification sent
- Jun 2, 2022
- Affected individuals
- 46,319
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 2d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 31, 2022→ Filed with AG: Jun 2, 20222d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.