DisclosureLens
MalwareRetail & ConsumerRetailRansomwareData ExfiltratedTargetedFinancial accountIdentity (basic)LowContained

Native Shoes

bd_776d1b78e048aa07 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 1, 2017

Filed

Aug 16, 2017

To disclose

11 weeks

Affected

22state residents only

Confidence

64%
Full breach record for Native Shoes

Native Shoes notified Montana residents of a malware attack on its website (nativeshoes.com) affecting purchases between April 28, 2015, and June 23, 2017. Compromised data included credit/debit card info, names, addresses, emails, and phone numbers. The company took systems offline, engaged forensic investigators, and offered one year of credit monitoring via CyberScout.

Incident timeline

undetected · 765 days
discovery → filing · 11 weeks / 76 days

Apr 28, 2015

Begins

Jun 1, 2017

Discovered

Aug 16, 2017

Filed

vs. sector median

+3 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed22 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.