DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCapture Stored DataData ExfiltratedTargetedPIIIdentity (basic)CredentialsFinancial accountLowContained

A&A Global Imports, Inc

bd_5a69bf70ff12f32c · schema v1 · pii pii-v1

Severity

Low

Discovered

Aug 17, 2018

Filed

Jan 9, 2019

To disclose

21 weeks

Affected

456state residents only

Linked

5 filings

Confidence

63%
Full breach record for A&A Global Imports, Inc

A&A Global Imports, Inc. notified customers that unauthorized code placed on its website between August 2017 and January 2019 may have captured personal and financial data. The company engaged forensic investigators and law enforcement, removed the code, and migrated its website platform. Affected data included names, contact info, credentials, and credit card details.

Incident timeline

undetected · 367 days
discovery → filing · 21 weeks / 145 days

Aug 15, 2017

Begins

Aug 17, 2018

Discovered

Jan 9, 2019

Filed

vs. sector median

+13 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Washington State AGJan 9 · first
Montana State AGJan 9 · first · this page

Pattern: first filing Jan 9 (WA), last Jan 14 (CA) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.