Pennsylvania General Store
bd_4c4e49ad2408dba3 · schema v1 · pii pii-v1
Full breach record for Pennsylvania General Store →2 incidents on filePennsylvania General Store notified customers of a data security incident involving its third-party e-commerce platform, CommerceV3. The incident occurred between November 24, 2021, and December 14, 2022, but was not discovered until June 6, 2023. Affected data may include names, email addresses, billing addresses, payment card numbers, CVV codes, and expiration dates. Approximately 46 Rhode Island residents were potentially impacted. CommerceV3 conducted a forensic investigation and implemented additional security measures.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2021
Begins
Jun 6, 2023
Discovered
Oct 27, 2023
Filed
vs. sector median
+13 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Maine State AGbd_0a85d081d999d2b52023-10-27Candidate
- Indiana State AGbd_229a53d6a2ad0b652023-09-15 · +42dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Sep 15 (IN), last Oct 27 (CA) — a 42-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.