STC Holdings LLC
bd_5f342a4f10d596f1 · schema v1 · pii pii-v1
STC Holdings (via TobaccoPipes.com) notified consumers of a data breach caused by a compromised third-party application (FreshClick) on its BigCommerce platform. The incident, occurring between Oct 15 and Nov 7, 2024, involved skimming of credit card information. STC Holdings uninstalled the app, secured systems, and engaged forensic investigators.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 15, 2024
Begins
Nov 8, 2024
Discovered
Dec 2, 2024
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Massachusetts State AGbd_11707656521ddf0f2024-11-28 · +4dVerified
- Maine State AGbd_f0cbd526669bc7082024-11-28 · +4dVerified
- Montana State AGbd_e11fc2bc71477d0e2024-11-27 · +5dCandidate
- Indiana State AGbd_f6e6a68a365e70d42024-11-27 · +5dVerified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- New Hampshire State AGbd_ff0dcc59156008642024-12-09 · +7dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Nov 27 (MT), last Dec 9 (NH) — a 12-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.