HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Hanna Andersson LLC
bd_4998136c4f4f4bce · schema v1 · pii pii-v1
Full breach record for Hanna Andersson LLC →Hanna Andersson, LLC reported a security incident involving unauthorized access to its e-commerce website between September 16 and November 11, 2019. An unauthorized third party accessed customer data including names, addresses, payment card numbers, CVV codes, and expiration dates. The company re-secured its platform, engaged forensic experts, and offered credit monitoring services to affected customers.
California clockDiscovered Nov 11, 2019 → Notified Jan 15, 202065d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1ff7c79f9d982a9aSouth Carolina State AGfiled 2020-01-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-186060
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 15, 2020
- Raw hash
- ddde7c8de797992e89f3c2ab765d699432a4aec39108dfa2bbeda1ef7353cae2
Reporting entity
- Name
- Hanna Andersson LLCnorm: hanna andersson
- Domain
- hannaandersson.com
- Industry
- Retail
Victim entity
- Name
- Hanna Andersson LLCnorm: hanna andersson
- Domain
- hannaandersson.com
- Industry
- Retail
Incident
- Discovered
- Nov 11, 2019
- Materiality determined
- —
- Notification sent
- Jan 15, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Cooperating with law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- CA 60-day late · 65d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 11, 2019→ Notified: Jan 15, 202065d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.