DisclosureLens
HackingRetailHacking OtherCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsMediumContained

Fioravanti Custom Products LLC

bd_72199beaf71b9a33 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 3, 2022

Filed

Feb 22, 2023

To disclose

20 weeks

Affected · nationwide

2,2937 in this filing

Linked

4 filings

Confidence

50%
Full breach record for Fioravanti Custom Products LLC

An unauthorized third party added malicious code to the company's website checkout page, allowing them to view and potentially capture customer information as it was entered. This included customer names, shipping addresses, payment card information, and email addresses. The code was active during two periods: from April 27 to May 22, 2022, and from October 11 to November 5, 2022.

Maine clockDiscovered Oct 3, 2022Filed with AG Feb 22, 2023142d ME AG >90d20 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 159 days
discovery → filing · 20 weeks / 142 days

Apr 27, 2022

Begins

Oct 3, 2022

Discovered

Feb 22, 2023

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Indiana State AGFeb 21 · first
Maine State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.