DisclosureLens
HackingRetail & ConsumerHealthcareRetailSkimmerData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

Lumenate Growth Ltd.

bd_7781ce6c52cef468 · schema v1 · pii pii-v1

Severity

Low

Discovered

May 14, 2026

Filed

Jul 17, 2026

To disclose

9 weeks

Affected

6state residents only

Confidence

66%
Full breach record for Lumenate Growth Ltd.

Lumenate Growth Ltd., a UK-based health and wellness company, discovered a payment-page skimmer (Magecart-style attack) on its website on May 14, 2026. Unauthorized access occurred between April 28 and May 14, 2026. The incident affected 6 New Hampshire residents, exposing names, credit/debit card numbers, and CVV codes. Lumenate secured its network, engaged forensic investigators, notified law enforcement and regulators (including the UK ICO), and mailed notifications to affected individuals on July 17, 2026, offering 12 months of credit monitoring.

Incident timeline

undetected · 16 days
discovery → filing · 9 weeks / 64 days

Apr 28, 2026

Begins

May 14, 2026

Discovered

Jul 17, 2026

Filed

vs. sector median

+2 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed6 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.