HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedTargetedPIIFINANCIAL_ACCOUNTCREDENTIALSMediumContained
SelectBlinds
bd_7dfc75746b157d31 · schema v1 · pii pii-v1
Full breach record for SelectBlinds →SelectBlinds notified the NH AG and ~1,206 residents of a data security incident. Beginning Jan 7, 2024, malware was embedded on the checkout page to scrape transaction data. SelectBlinds detected unusual activity on Sep 28, 2024, and completed an investigation on Oct 10, 2024. Affected data includes personal and payment information. SelectBlinds locked user accounts, engaged forensic experts, and notified law enforcement.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_1923f9007672926fMaine State AGfiled 2024-10-31Verified
- bd_1af605e003eeaadeVermont State AGfiled 2024-10-31Verified
- bd_302d1ff6caa823bcDelaware State AGfiled 2024-10-31Candidate
- bd_3d0c0642d4dc639aMontana State AGfiled 2024-10-31Verified
Show 6 more filings ↓Show fewer ↑up to 24d gap
- bd_41a17bd100035b7fIndiana State AGfiled 2024-10-31Verified
- bd_7ed9e87de0e792e1California State AGfiled 2024-10-31Verified
- bd_dd07d60af013eeadOregon State AGfiled 2024-10-31Verified
- bd_e041a012af34a2d7Washington State AGfiled 2024-10-31Verified
- bd_8c0eda7f606a2408Vermont State AGfiled 2024-10-29(2d gap)Candidate
- bd_8a9d4c7ca3c46cc5Delaware State AGfiled 2024-10-07(24d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/selectblinds-20241031.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 31, 2024
- Raw hash
- 2577e80a6f4509dd09043de161f222a2a4fafd4333d17e8114b25d655efc444e
Reporting entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Victim entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Incident
- Discovered
- Sep 28, 2024
- Materiality determined
- Oct 10, 2024
- Notification sent
- Oct 31, 2024
- Affected individuals
- 1,206
- Data types
- PIIFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated CollectionT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney GeneralNotified and is cooperating with federal law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.