Bombas
bd_7c07b8808eed98d9 · schema v1 · pii pii-v1
Full breach record for Bombas →4 incidents on fileBombas, LLC notified the NH AG of a 2015 malware incident on its Magento e-commerce platform affecting ~41,000 customers (254 NH residents). Malware existed from Sept 2013 to Feb 2015. Bombas migrated to Shopify and offers 24 months of credit monitoring via Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 1, 2013
Begins
Jan 1, 2018
Discovered
May 18, 2018
Filed
vs. sector median
+12 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_632c602d45662e4e2018-05-18Candidate
- Oregon State AGbd_9ced2a7275ad71ad2018-05-18Verified
- California State AGbd_a8afdb78c007e7582018-05-18Verified
- Massachusetts State AGbd_f7abae59dfdafb742018-05-21 · +3dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.