Blundstone (U.S.A.) Inc.
bd_714ab241355383f2 · schema v1 · pii pii-v1
Full breach record for Blundstone (U.S.A.) Inc. →2 incidents on fileBlundstone (U.S.A.) Inc. experienced a security incident where an unauthorized third party exploited a vulnerability in the Adobe Commerce platform to install malicious code on the e-commerce checkout page. This allowed the collection of contact and payment information from July 7, 2024, to August 14, 2024. The incident was discovered on August 15, 2024. Affected data includes names, addresses, phone numbers, and payment card details (including CVV). Blundstone removed the malicious code, applied patches, and engaged a cybersecurity firm.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 7, 2024
Begins
Aug 15, 2024
Discovered
Sep 20, 2024
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Massachusetts State AGbd_40bb3d986f417e812024-09-20Verified
- Maine State AGbd_7a9af778c88c72152024-09-20Verified
- Vermont State AGbd_d52977427ecd93442024-09-20Verified
- Montana State AGbd_4d7eaaf90dd137d92024-09-14 · +6dCandidate
Show 2 more filings ↓Show fewer ↑up to 7d gap
- Indiana State AGbd_f45176f5ded33fe92024-09-14 · +6dVerified
- New Hampshire State AGbd_2676fe0caf8e95612024-09-13 · +7dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Sep 13 (NH), last Sep 20 (CA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.