HackingSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Pennsylvania General Store
bd_4c4e49ad2408dba3 · schema v1 · pii pii-v1
Full breach record for Pennsylvania General Store →Pennsylvania General Store notified customers of a data security incident involving its third-party e-commerce platform, CommerceV3. The incident occurred between November 24, 2021, and December 14, 2022, but was not discovered until June 6, 2023. Affected data may include names, email addresses, billing addresses, payment card numbers, CVV codes, and expiration dates. Approximately 46 Rhode Island residents were potentially impacted. CommerceV3 conducted a forensic investigation and implemented additional security measures.
California clockDiscovered Jun 6, 2023 → Notified Sep 15, 2023101d ✗ CA 60-day late20 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0a85d081d999d2b5Maine State AGfiled 2023-10-27Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-575814
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 27, 2023
- Raw hash
- e8cb7301b6058016f13a405222bae20a4b4467998e9b3c534c4736d9839cfa51
Reporting entity
- Name
- Pennsylvania General Storenorm: pennsylvania general store
Victim entity
- Name
- Pennsylvania General Storenorm: pennsylvania general store
Incident
- Discovered
- Jun 6, 2023
- Materiality determined
- —
- Notification sent
- Sep 15, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Third party
- via CommerceV3
Compliance
- Time to disclose
- 20 weeks(143 days from discovery to filing)
- Compliance flags
- CA 60-day late · 101d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 6, 2023→ Notified: Sep 15, 2023101d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.