DisclosureLens
HackingRetail & ConsumerRetailSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIdentity (basic)Financial accountFinancial credentialsLowContained

Pennsylvania General Store

bd_4c4e49ad2408dba3 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 6, 2023

Filed

Oct 27, 2023

To disclose

20 weeks

Affected

Not disclosed

Linked

3 filings

Confidence

65%
Full breach record for Pennsylvania General Store2 incidents on file

Pennsylvania General Store notified customers of a data security incident involving its third-party e-commerce platform, CommerceV3. The incident occurred between November 24, 2021, and December 14, 2022, but was not discovered until June 6, 2023. Affected data may include names, email addresses, billing addresses, payment card numbers, CVV codes, and expiration dates. Approximately 46 Rhode Island residents were potentially impacted. CommerceV3 conducted a forensic investigation and implemented additional security measures.

California clockDiscovered Jun 6, 2023Notified Sep 15, 2023101d CA 60-day late20 weeks discovery → filing

Incident timeline

undetected · 559 days
discovery → filing · 20 weeks / 143 days

Nov 24, 2021

Begins

Jun 6, 2023

Discovered

Oct 27, 2023

Filed

vs. sector median

+13 wks slower

This filing is one of 3 about the same incident.View merged incident
Part of CommerceV3 supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Indiana State AGSep 15 · first
California State AG+42d · this page

Pattern: first filing Sep 15 (IN), last Oct 27 (CA) — a 42-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.