HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
LEM
bd_7ebe8a22e9e79b42 · schema v1 · pii pii-v1
Full breach record for LEM →LEM Products Direct LLC notified customers that an unauthorized party accessed its third-party e-commerce platform, CommerceV3, between November 24, 2021, and December 14, 2022. The incident potentially exposed payment card information, including card numbers, expiration dates, and CVVs, along with names, email addresses, and billing addresses. CommerceV3 discovered the access on May 3, 2023, and notified LEM on June 6, 2023. LEM implemented additional security measures and advised customers to monitor their accounts.
California clockDiscovered Jun 6, 2023 → Notified Jul 13, 202337d ✓ CA 60-day OK5 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2a62e25c2be5ad4eMontana State AGfiled 2023-07-13Verified
- bd_6103ca441e86a097New Hampshire State AGfiled 2023-07-13Verified
- bd_3ec2e221860bb57eOregon State AGfiled 2023-07-20(7d gap)Verified
- bd_86dac13b5049e9baWashington State AGfiled 2023-07-06(7d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570247
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 13, 2023
- Raw hash
- ed663723e3f804be5fe15fab9d1eba6d36f83d1b84f63bb4b74c2df2499f79ed
Reporting entity
- Name
- LEMnorm: lem
- Domain
- lem.com
Victim entity
- Name
- LEMnorm: lem
- Domain
- lem.com
Incident
- Discovered
- Jun 6, 2023
- Materiality determined
- —
- Notification sent
- Jul 13, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via CommerceV3
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 37d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 6, 2023→ Notified: Jul 13, 202337d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.