DisclosureLens
MalwareRetail & ConsumerRetailData ExfiltratedCustomer Data InvolvedDelayed DiscoveryFinancial accountIdentity (basic)LowContained

Native Canada Footwear Ltd

bd_84277d36ba17dbca · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 30, 2017

Filed

Aug 16, 2017

To disclose

7 weeks

Affected

Not disclosed

Linked

4 filings

Confidence

64%
Full breach record for Native Canada Footwear Ltd

Native Canada Footwear, Ltd. disclosed a malware attack on its website (nativeshoes.com) that potentially compromised payment card information (Visa/Mastercard) and personal data (name, address, email, phone) of customers who made purchases between April 28, 2015, and June 23, 2017. The company became aware of the vulnerability in late June 2017. Affected individuals were offered one year of credit monitoring. The incident did not affect PayPal transactions or purchases made through online partners or brick-and-mortar stores.

California clockDiscovered Jun 30, 2017Notified Aug 16, 201747d CA 60-day OK7 weeks discovery → filing

Incident timeline

undetected · 794 days
discovery → filing · 7 weeks / 47 days

Apr 28, 2015

Begins

Jun 30, 2017

Discovered

Aug 16, 2017

Filed

vs. sector median

1 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
New Hampshire State AGAug 16 · first
Massachusetts State AGAug 16 · first
California State AGAug 16 · first · this page

Pattern: first filing Aug 16 (NH), last Sep 8 (OR) — a 23-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.