The C.H. Hanson Company
bd_73f4f18616a9e8e1 · schema v1 · pii pii-v1
Full breach record for The C.H. Hanson Company →The C.H. Hanson Company notified the NH AG of a data incident involving its third-party e-commerce provider, CommerceV3. Unauthorized access occurred between Nov 24, 2021 and Dec 14, 2022. CommerceV3 discovered cardholder data access on May 3, 2023. Notification began Oct 19, 2023, affecting 2 NH residents. Data included names, emails, billing addresses, and payment card details (PAN, CVV, expiry). C.H. Hanson terminated the relationship with CommerceV3 and migrated platforms.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2021
Begins
May 3, 2023
Discovered
Nov 1, 2023
Filed
vs. sector median
+18 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_e02e33c5d043168b2023-10-30 · +2dVerified
- Montana State AGbd_d1505662e1f60c462023-10-20 · +12dCandidate
- Indiana State AGbd_7f3cdc920ce3aa342023-10-19 · +13dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Oct 19 (IN), last Nov 1 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.