DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountLowContained

VACPARTSWAREHOUSE.COM

bd_7fbc3cbc26c5d303 · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 22, 2026

Filed

May 20, 2026

To disclose

28 days

Affected

221state residents only

Linked

11 filings

Confidence

66%
Full breach record for VACPARTSWAREHOUSE.COM

VacPartsWarehouse.com LLC notified the New Hampshire Attorney General of a data breach affecting 221 state residents. Unauthorized actors accessed the online shopping platform between October 31 and December 12, 2025, potentially acquiring names, addresses, and payment card details (including CVV). The company discovered the incident on April 22, 2026, and mailed notifications on May 20, 2026. No ransomware or malware was involved; the attack vector appears to be exploitation of the public-facing application.

Incident timeline

undetected · 173 days
discovery → filing · 28 days

Oct 31, 2025

Begins

Apr 22, 2026

Discovered

May 20, 2026

Filed

vs. sector median

4 wks faster

This filing is one of 11 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filingsup to 19d gap

Filing propagation · 11 filings · 11 states

View merged incident ↗

Pattern: first filing May 1 (IL), last May 22 (TX) — a 21-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.