Blundstone (U.S.A.) Inc.
bd_4d7eaaf90dd137d9 · schema v1 · pii pii-v1
Full breach record for Blundstone (U.S.A.) Inc. →2 incidents on fileBlundstone (U.S.A.) Inc. notified Montana residents of a data breach involving its Adobe Commerce e-commerce platform. An unauthorized third party exploited a vulnerability to install malicious code that duplicated the checkout page and captured customer PII and payment card data (including CVV) between July 7 and August 14, 2024. Blundstone discovered the incident on August 15, 2024, removed the malware, patched the vulnerability, and engaged forensic counsel.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 7, 2024
Begins
Aug 15, 2024
Discovered
Sep 14, 2024
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Indiana State AGbd_f45176f5ded33fe92024-09-14Verified
- New Hampshire State AGbd_2676fe0caf8e95612024-09-13 · +1dVerified
- Massachusetts State AGbd_40bb3d986f417e812024-09-20 · +6dVerified
- California State AGbd_714ab241355383f22024-09-20 · +6dVerified
Show 2 more filings ↓Show fewer ↑up to 6d gap
- Maine State AGbd_7a9af778c88c72152024-09-20 · +6dVerified
- Vermont State AGbd_d52977427ecd93442024-09-20 · +6dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Sep 13 (NH), last Sep 20 (VT) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.