Roots & Harvest Direct LLC
bd_50caf27259718c06 · schema v1 · pii pii-v1
Full breach record for Roots & Harvest Direct LLC →Roots & Harvest Direct LLC notified customers that its third-party e-commerce platform provider, CommerceV3, experienced unauthorized access to systems between Nov 2021 and Dec 2022. Cardholder data including names, emails, billing addresses, card numbers, and CVVs were potentially accessed. CommerceV3 conducted forensic investigations and implemented additional security measures.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2021
Begins
May 3, 2023
Discovered
Jul 13, 2023
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_0254195321496ea82023-07-13Verified
- New Hampshire State AGbd_2ce5ac206fc610092023-07-13Verified
- Maine State AGbd_cbec415dc44f19ab2023-07-14 · +1dVerified
- Indiana State AGbd_7a3b00926d3f02aa2023-07-06 · +7dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 6 (IN), last Jul 14 (ME) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.