HackingRetail & ConsumerRetailVulnerability ExploitCapture App DataN-DayData ExfiltratedCustomer Data InvolvedPIIPCILowContained
Blundstone (U.S.A.) Inc.
bd_7a9af778c88c7215 · schema v1 · pii pii-v1
Full breach record for Blundstone (U.S.A.) Inc. →Blundstone (U.S.A.) Inc. disclosed a web skimming incident affecting its Adobe Commerce (Magento) e-commerce platform. An unauthorized third party exploited a vulnerability in the platform between July 7, 2024 and August 14, 2024, installing malicious code that duplicated the checkout webpage to capture customer contact and payment card information at point of sale. Discovered August 15, 2024; 77 Maine residents and 6,156 total individuals were affected.
Maine clockDiscovered Aug 15, 2024 → Filed with AG Sep 20, 202436d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_714ab241355383f2California State AGfiled 2024-09-20Verified
- bd_d52977427ecd9344Vermont State AGfiled 2024-09-20Verified
- bd_4d7eaaf90dd137d9Montana State AGfiled 2024-09-14(6d gap)Candidate
- bd_f45176f5ded33fe9Indiana State AGfiled 2024-09-14(6d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_2676fe0caf8e9561New Hampshire State AGfiled 2024-09-13(7d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/ece05881-b4e1-4a4d-a827-3554b3196836.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 20, 2024
- Raw hash
- 59ae7f14e19a26752c1ca17223353af84780c5f5bf7e22302f3c4206814d981a
Reporting entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
- Industry
- Retail footwear e-commerce
Victim entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
- Industry
- Retail footwear e-commerce
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Aug 15, 2024
- Materiality determined
- —
- Notification sent
- Sep 14, 2024
- Affected individuals
- 77
- Data types
- PIIPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056.003 Web Portal CaptureT1059 Command and Scripting Interpreter
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- ME AG >30d · 36d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 15, 2024→ Filed with AG: Sep 20, 202436d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.