DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsTargetedData ExfiltratedFinancial accountIdentity (basic)PIIMediumContained

Rainier Arms

bd_7a232b15ca1c34f3 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 21, 2022

Filed

Jun 2, 2022

To disclose

6 weeks

Affected

6,493state residents only

Linked

8 filings

Confidence

70%
Full breach record for Rainier Arms2 incidents on file

Rainier Arms, a retail firearms dealer, notified Washington AG of a cyberattack where malicious code on its website captured payment card information of 6,493 residents between June 2021 and January 2022. The breach was discovered on April 21, 2022, via forensic review. Notices were sent June 2, 2022.

Washington clock WA AG >30d6 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 324 days
discovery → filing · 6 weeks / 42 days

Jun 1, 2021

Begins

Apr 21, 2022

Discovered

Jun 2, 2022

Filed

vs. sector median

1 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filings

Filing propagation · 8 filings · 8 states

View merged incident ↗
Maine State AGJun 2 · first
Oregon State AGJun 2 · first
Montana State AGJun 2 · first
Indiana State AGJun 2 · first
California State AGJun 2 · first
Washington State AGJun 2 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.