SelectBlinds
bd_7ed9e87de0e792e1 · schema v1 · pii pii-v1
Full breach record for SelectBlinds →SelectBlinds, an online retailer of custom window coverings, experienced a data breach beginning on or about January 7, 2024. An unauthorized third party embedded malware on the SelectBlinds website, allowing data scraping of sales transactions entered on the checkout page. The company became aware of the incident on September 28, 2024. Affected data includes names, emails, shipping/billing addresses, phone numbers, payment card numbers, expiration dates, CVV codes, and potentially usernames/passwords. The incident was contained, malware eradicated, and user accounts temporarily locked. No specific count of affected individuals was disclosed in the provided notice samples.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_1923f9007672926fMaine State AGfiled 2024-10-31Verified
- bd_1af605e003eeaadeVermont State AGfiled 2024-10-31Verified
- bd_302d1ff6caa823bcDelaware State AGfiled 2024-10-31Candidate
- bd_3d0c0642d4dc639aMontana State AGfiled 2024-10-31Verified
Show 6 more filings ↓Show fewer ↑up to 24d gap
- bd_41a17bd100035b7fIndiana State AGfiled 2024-10-31Verified
- bd_7dfc75746b157d31New Hampshire State AGfiled 2024-10-31Verified
- bd_dd07d60af013eeadOregon State AGfiled 2024-10-31Verified
- bd_e041a012af34a2d7Washington State AGfiled 2024-10-31Verified
- bd_8c0eda7f606a2408Vermont State AGfiled 2024-10-29(2d gap)Candidate
- bd_8a9d4c7ca3c46cc5Delaware State AGfiled 2024-10-07(24d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-594202
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 31, 2024
- Raw hash
- 0ce4702722cb3e24d4000ed60ef697d07c17f8874308d04ef9405cb96c2e1aa0
Reporting entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Victim entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Incident
- Discovered
- Sep 28, 2024
- Materiality determined
- —
- Notification sent
- Oct 31, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 33d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 28, 2024→ Notified: Oct 31, 202433d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.