HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Lee Valley Tools
bd_66e2c81b16d18c74 · schema v1 · pii pii-v1
Full breach record for Lee Valley Tools →Lee Valley Tools, Ltd. reported a cybersecurity event affecting 774 New Hampshire residents. Unauthorized access occurred between October 8, 2024, and March 12, 2025, via a vulnerability in Sitecore CMS that allowed an attacker to inject code capturing payment card data at checkout. Lee Valley detected the incident on March 12, 2025, engaged forensic experts, notified law enforcement, and is offering credit monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_282e04dbb9abf769California State AGfiled 2025-04-09Candidate
- bd_9a4c3955773a1f40Vermont State AGfiled 2025-04-15(6d gap)Verified
- bd_fead9dabf61f395cIndiana State AGfiled 2025-04-15(6d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lee-valley-tools-20250409.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 9, 2025
- Raw hash
- 064a68a715bf48836353435c9c415dff38d81e21b28b540218d89ff50aefc7d1
Reporting entity
- Name
- Lee Valley Toolsnorm: lee valley tools
- Domain
- leevalley.com
Victim entity
- Name
- Lee Valley Toolsnorm: lee valley tools
- Domain
- leevalley.com
Incident
- Discovered
- Mar 12, 2025
- Materiality determined
- Mar 28, 2025
- Notification sent
- Apr 9, 2025
- Affected individuals
- 774
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.