Blundstone (U.S.A.) Inc.
bd_7a9af778c88c7215 · schema v1 · pii pii-v1
Full breach record for Blundstone (U.S.A.) Inc. →2 incidents on fileBlundstone (U.S.A.) Inc. reported a data breach affecting 6,156 individuals, including 77 Maine residents. Unauthorized access occurred between July 7, 2024, and August 14, 2024, via exploitation of a vulnerability in the Adobe Commerce platform. The attacker installed malicious code to capture customer names, addresses, phone numbers, and payment card information (including CVV). Blundstone removed the code, patched the vulnerability, and engaged forensic counsel. Notices were sent on September 14, 2024.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 7, 2024
Begins
Aug 15, 2024
Discovered
Sep 20, 2024
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Massachusetts State AGbd_40bb3d986f417e812024-09-20Verified
- California State AGbd_714ab241355383f22024-09-20Verified
- Vermont State AGbd_d52977427ecd93442024-09-20Verified
- Montana State AGbd_4d7eaaf90dd137d92024-09-14 · +6dCandidate
Show 2 more filings ↓Show fewer ↑up to 7d gap
- Indiana State AGbd_f45176f5ded33fe92024-09-14 · +6dVerified
- New Hampshire State AGbd_2676fe0caf8e95612024-09-13 · +7dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Sep 13 (NH), last Sep 20 (ME) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.