DisclosureLens
HackingManufacturingRetail & ConsumerManufacturingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)Identity (basic)Financial accountLowActive

Bimba LLC

bd_4051af5c7c3e12f1 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Dec 28, 2020

To disclose

Affected

844

Confidence

66%
Full breach record for Bimba LLC2 incidents on file

Bimba LLC (d/b/a Bimba Manufacturing) notified the NH Attorney General of a security incident involving its third-party cloud hosting provider. Between Aug 21 and Nov 13, 2020, an unauthorized user exploited a server vulnerability to insert malicious code, diverting unencrypted e-commerce transaction data (names, addresses, credit card numbers, CVV) to the attacker. 11 NH residents were affected; 844 total transactions occurred. Bimba offered 24 months of Experian IdentityWorks.

Incident timeline

Aug 21, 2020

Begins

Dec 28, 2020

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed844 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.