HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Lancaster Archery Supply
bd_4b140d91990b59ed · schema v1 · pii pii-v1
Full breach record for Lancaster Archery Supply →Lancaster Archery Supply, Inc. disclosed a data breach affecting approximately 3,366 California residents. Payment card information (cardholder name, number, expiration date, CVV) was compromised from July 4, 2018, through February 16, 2019, via unauthorized access to its public-facing websites. The company engaged forensic investigators and law enforcement, remediated the vulnerability, and mailed notices to affected individuals.
California clockDiscovered Apr 3, 2019 → Notified Apr 25, 201922d ✓ CA 60-day OK23 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_41719e6a459d7f01Washington State AGfiled 2019-04-26Candidate
- bd_5473aaec2d7b5b52Oregon State AGfiled 2019-04-26Verified
- bd_e5e8f0d9c4537b73Montana State AGfiled 2019-04-26Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-146707
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 26, 2019
- Raw hash
- dd0c1c226978451599bb612e57b2d620a8cc760721763e1e3c0f7175fce69bf8
Reporting entity
- Name
- Lancaster Archery Supplynorm: lancaster archery supply
- Domain
- lancasterarchery.com
- Industry
- Retail
Victim entity
- Name
- Lancaster Archery Supplynorm: lancaster archery supply
- Domain
- lancasterarchery.com
- Industry
- Retail
Incident
- Discovered
- Apr 3, 2019
- Materiality determined
- —
- Notification sent
- Apr 25, 2019
- Affected individuals
- 3,366
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided written notice to state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 22d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 3, 2019→ Notified: Apr 25, 201922d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.