HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICLowContained
Gapbuster Worldwide Pty Ltd
bd_3f82215f16bf076f · schema v1 · pii pii-v1
Full breach record for Gapbuster Worldwide Pty Ltd →Gapbuster Worldwide notified Vermont AG of a May 30, 2024 data breach involving third-party vendor Nectar Desk. Cloud storage containing mystery shoppers' names, emails, and mobile numbers was accessed. Incident contained; vendor tracking downloads to prevent further distribution.
Vermont clock✓ VT AG ≤14 bday3 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_052327572fa08ab5Idaho State AGfiled 2024-06-04(2d gap)Candidate
- bd_085bfdee92dbd5d4New Hampshire State AGfiled 2024-06-04(2d gap)Verified
- bd_a85b7e063d378f4eCalifornia State AGfiled 2024-06-04(2d gap)Verified
- bd_9e297168849119baMaine State AGfiled 2024-06-05(3d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-06-02-gapbuster-worldwide-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 2, 2024
- Raw hash
- 8957e47e0a31f20dd768c4ff3d19b658e2fa432065e49879d354302fa6f9707e
Reporting entity
- Name
- Gapbuster Worldwide Pty Ltdnorm: gapbuster worldwide
- Domain
- gbw.solutions
Victim entity
- Name
- Gapbuster Worldwide Pty Ltdnorm: gapbuster worldwide
- Domain
- gbw.solutions
Incident
- Discovered
- May 30, 2024
- Materiality determined
- —
- Notification sent
- Jun 2, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Nectar Desk
- Initial access
- supply_chain
Compliance
- Time to disclose
- 3 days(3 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.