HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Blundstone (U.S.A.) Inc.
bd_714ab241355383f2 · schema v1 · pii pii-v1
Full breach record for Blundstone (U.S.A.) Inc. →Blundstone (U.S.A.) Inc. experienced a security incident where an unauthorized third party exploited a vulnerability in the Adobe Commerce platform to install malicious code on the e-commerce checkout page. This allowed the collection of contact and payment information from July 7, 2024, to August 14, 2024. The incident was discovered on August 15, 2024. Affected data includes names, addresses, phone numbers, and payment card details (including CVV). Blundstone removed the malicious code, applied patches, and engaged a cybersecurity firm.
California clockDiscovered Aug 15, 2024 → Notified Aug 16, 20241d ✓ CA 60-day OK5 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_7a9af778c88c7215Maine State AGfiled 2024-09-20Verified
- bd_d52977427ecd9344Vermont State AGfiled 2024-09-20Verified
- bd_4d7eaaf90dd137d9Montana State AGfiled 2024-09-14(6d gap)Candidate
- bd_f45176f5ded33fe9Indiana State AGfiled 2024-09-14(6d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_2676fe0caf8e9561New Hampshire State AGfiled 2024-09-13(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-592140
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 20, 2024
- Raw hash
- 862593b194839d2692a0ffc904758d652b9a984e18bc0e01a810b7a611b63540
Reporting entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
Victim entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
Incident
- Discovered
- Aug 15, 2024
- Materiality determined
- —
- Notification sent
- Aug 16, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 1d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 15, 2024→ Notified: Aug 16, 20241d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.