Bombas
bd_632c602d45662e4e · schema v1 · pii pii-v1
Full breach record for Bombas →4 incidents on fileBombas, LLC notified customers of a data breach involving malware on its e-commerce platform. The malware existed from the site's launch on September 1, 2013, until removal on February 9, 2015. Approximately 41,000 customers who made credit card purchases during this period were affected. Data potentially included names, addresses, and credit card information. Bombas engaged Kroll to provide two years of free identity monitoring and migrated to a new platform.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 1, 2013
Begins
Jan 15, 2015
Discovered
May 18, 2018
Filed
vs. sector median
+167 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- New Hampshire State AGbd_7c07b8808eed98d92018-05-18Verified
- Oregon State AGbd_9ced2a7275ad71ad2018-05-18Verified
- California State AGbd_a8afdb78c007e7582018-05-18Verified
- Massachusetts State AGbd_f7abae59dfdafb742018-05-21 · +3dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.