DisclosureLens
MalwareRetail & ConsumerRetailInfostealerData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

Ballistic Products, Inc.

bd_6af97512dc8d42cb · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 26, 2022

Filed

Sep 5, 2022

To disclose

6 weeks

Affected

431state residents only

Linked

8 filings

Confidence

64%
Full breach record for Ballistic Products, Inc.

Ballistic Products, Inc. issued a supplemental notice regarding a third-party vendor malware incident. Malware on the vendor's servers captured payment card data, names, and billing addresses from customers who shopped between Sept 18, 2020, and Feb 3, 2022. The vendor removed the malware and engaged forensic experts. Ballistic is offering credit monitoring and identity theft protection services.

Incident timeline

undetected · 676 days
discovery → filing · 6 weeks / 41 days

Sep 18, 2020

Begins

Jul 26, 2022

Discovered

Sep 5, 2022

Filed

vs. sector median

2 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 16d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing Sep 1 (IN), last Sep 21 (MA) — a 20-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.