HackingVulnerability ExploitCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Nuna Baby Essentials, Inc.
bd_7eee5014fe282a4d · schema v1 · pii pii-v1
Full breach record for Nuna Baby Essentials, Inc. →Nuna Baby Essentials, Inc. notified the Maryland Attorney General of a data event affecting 269 Maryland residents. Suspicious activity on the company's website payment platform between September 8 and December 6, 2024, led to the unauthorized access of names, billing addresses, and payment card details. Nuna removed unauthorized code and enhanced website protections.
Maryland clock⏱ MD AG >30d11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_0b7b92e6170b3970Montana State AGfiled 2025-02-21Candidate
- bd_2dd65c8ad427d077Washington State AGfiled 2025-02-21Verified
- bd_863f7030737ba663New Hampshire State AGfiled 2025-02-21Verified
- bd_88ed36dc3d3a9accIndiana State AGfiled 2025-02-21Verified
Show 4 more filings ↓Show fewer ↑
- bd_b3eda8f7cf864f88Vermont State AGfiled 2025-02-21Verified
- bd_c3eebdb216aeccb8Oregon State AGfiled 2025-02-21Verified
- bd_d4c0418644cd4190California State AGfiled 2025-02-21Verified
- bd_efccb14d68a965e4Maine State AGfiled 2025-02-21Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376397.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 21, 2025
- Raw hash
- 0bd1f272c3b34f9872404c0858c5012f3b23118ec789390eae8ad96d5bddd5da
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Nuna Baby Essentials, Inc.norm: nuna baby essentials
- Domain
- nunalife.com
Incident
- Discovered
- Dec 6, 2024
- Materiality determined
- Feb 21, 2025
- Notification sent
- Feb 21, 2025
- Affected individuals
- 269
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided written notice of this incident to relevant state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.