HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Heirloom Home
bd_3c6bde4e9111e483 · schema v1 · pii pii-v1
Full breach record for Heirloom Home →Heirloom Roses, a commercial entity, reported a cybersecurity incident occurring between February 24, 2021, and October 26, 2021. The breach involved malicious code placed on the company's website, resulting in unauthorized access to customer data. Approximately 52,206 individuals were affected, including 243 Maine residents. Compromised data included names and financial account or credit/debit card numbers. The company provided written notification and offered one year of credit monitoring and identity theft protection services through Kroll.
Maine clockDiscovered Aug 12, 2021 → Filed with AG Dec 17, 2021127d ✗ ME AG >90d18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed52,206 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/099da94b-a3fd-4237-8808-6846aa4ccaac.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 17, 2021
- Raw hash
- e3e36a914ba7d278c46520b645c0e4471831950791806f088424ab95a67c3242
Reporting entity
- Name
- Ciprianinorm: cipriani
- Domain
- cipriani.com
Victim entity
- Name
- Heirloom Homenorm: heirloom home
- Domain
- theheirloomcollective.us
Incident
- Discovered
- Aug 12, 2021
- Materiality determined
- —
- Notification sent
- Dec 17, 2021
- Affected individuals
- 52,206
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- ME AG >90d · 127dME resident >60d · 127d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 12, 2021→ Filed with AG: Dec 17, 2021127d 90 days ME AG >90d Maine Discovered: Aug 12, 2021→ Notified: Dec 17, 2021127d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.