Lime Crime, Inc.
bd_5cb99b44ae885b94 · schema v1 · pii pii-v1
Full breach record for Lime Crime, Inc. →Lime Crime, Inc. disclosed that unauthorized individuals installed malicious software on its website server on October 4, 2014. The company discovered the incident on February 11, 2015, after a forensic investigation. The malware potentially compromised personal information of customers who made purchases between October 4, 2014, and February 15, 2015. Affected data includes names, addresses, usernames, passwords, and payment card details (account numbers, expiration dates, security codes) for credit/debit card users. PayPal users had their usernames and passwords compromised but not financial data. Lime Crime took the website offline, replaced its e-commerce platform with a PCI-compliant one, reset passwords, and offered one year of identity protection services via Experian. The incident has been contained and eliminated.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 4, 2014
Begins
Feb 11, 2015
Discovered
Feb 24, 2015
Filed
vs. sector median
6 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_f5f2c46a35423c952015-02-27 · +3dVerified
- New Hampshire State AGbd_29e88ea99e1580f02015-03-10 · +14dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Feb 24 (CA), last Mar 10 (NH) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.