DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

LEM Products Direct LLC

bd_7ebe8a22e9e79b42 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 6, 2023

Filed

Jul 13, 2023

To disclose

5 weeks

Affected

Not disclosed

Linked

6 filings

Confidence

64%
Full breach record for LEM Products Direct LLC3 incidents on file

LEM Products Direct LLC notified customers that an unauthorized party accessed its third-party e-commerce platform, CommerceV3, between November 24, 2021, and December 14, 2022. The incident potentially exposed payment card information, including card numbers, expiration dates, and CVVs, along with names, email addresses, and billing addresses. CommerceV3 discovered the access on May 3, 2023, and notified LEM on June 6, 2023. LEM implemented additional security measures and advised customers to monitor their accounts.

California clockDiscovered Jun 6, 2023Notified Jul 13, 202337d CA 60-day OK5 weeks discovery → filing

Incident timeline

undetected · 559 days
discovery → filing · 5 weeks / 37 days

Nov 24, 2021

Begins

Jun 6, 2023

Discovered

Jul 13, 2023

Filed

vs. sector median

2 wks faster

This filing is one of 6 about the same incident.View merged incident
Part of CommerceV3 supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 7d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Washington State AGJul 6 · first
Indiana State AGJul 6 · first
California State AG+7d · this page

Pattern: first filing Jul 6 (WA), last Jul 20 (OR) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.