HackingVulnerability ExploitTargetedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Blundstone (U.S.A.) Inc.
bd_49ee952bc8d3948e · schema v1 · pii pii-v1
Full breach record for Blundstone (U.S.A.) Inc. →Blundstone (U.S.A.) Inc. disclosed a data breach affecting customers who made online purchases. An unauthorized third party exploited a vulnerability in a plug-in on the Adobe Commerce (Magento) platform on November 12, 2024, to install malicious code that duplicated the checkout page. The attacker collected personal and payment information, including names, addresses, phone numbers, and payment card details with CVVs, for a period of 2.5 hours. Blundstone removed the malicious code, applied security patches, and engaged outside cybersecurity and legal counsel.
Vermont clock✓ VT AG ≤14 bday16 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_c014c430a3e9606bIndiana State AGfiled 2024-11-28Verified
- bd_932d771742e187fbMontana State AGfiled 2024-12-04(6d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-11-28-blundstone-usa-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 28, 2024
- Raw hash
- dd86035ce454772babc18c29d51ff51ad5bb2a6c28dbea9835195453ebe2c477
Reporting entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
Victim entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
Incident
- Discovered
- Nov 12, 2024
- Materiality determined
- —
- Notification sent
- Nov 28, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.