DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedPIIIdentity (basic)PCIFinancial accountMediumContained

Filters Fast, LLC

bd_5ca8f5e5063b26d4 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 1, 2020

Filed

Aug 14, 2020

To disclose

28 weeks

Affected

6,584state residents only

Linked

9 filings

Confidence

69%
Full breach record for Filters Fast, LLC

Filters Fast, LLC notified Washington AG of a cyberattack on its e-commerce site. Attackers injected malicious code on July 15, 2019, capturing customer names, addresses, and payment card info during checkout. The code was removed July 10, 2020. 6,584 Washington residents were notified in August 2020. Identity theft protection services were offered.

Incident timeline

undetected · 201 days
discovery → filing · 28 weeks / 195 days

Jul 15, 2019

Begins

Feb 1, 2020

Discovered

Aug 14, 2020

Filed

vs. sector median

+20 wks slower

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 13d gap

Filing propagation · 9 filings · 9 states

View merged incident ↗
Montana State AGAug 14 · first
Indiana State AGAug 14 · first
California State AGAug 14 · first
Oregon State AGAug 14 · first
Massachusetts State AGAug 14 · first
Washington State AGAug 14 · first · this page

Pattern: first filing Aug 14 (MT), last Aug 27 (DE) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.