HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Blade HQ
bd_8a34f4aeb2a21f7e · schema v1 · pii pii-v1
Full breach record for Blade HQ →Blade HQ, a retail merchant, notified customers of a data breach affecting bladehq.com and related sites. Unauthorized intruders gained access to servers between January 7, 2021, and April 11, 2021, uploading malware to skim customer transaction data. Affected data included names, addresses, emails, and credit/debit card numbers with CVV codes. Blade HQ engaged forensic investigators, removed the malware, deployed new servers, and implemented additional security measures. No actual misuse of information was confirmed.
California clockDiscovered Mar 22, 2021 → Notified Apr 19, 202128d ✓ CA 60-day OK28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_4de597f4ac5ffcf4Oregon State AGfiled 2021-04-19Candidate
- bd_981135236a66aab2Washington State AGfiled 2021-04-19Verified
- bd_a449fbb90cda4b3eMontana State AGfiled 2021-04-20(1d gap)Verified
- bd_bf35a6f255d2a15bMaine State AGfiled 2021-04-20(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-540050
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 19, 2021
- Raw hash
- 92bbf4bd6d5f3a1da6105704aaa70c34cee0c264b20f3ccbd1fbf3e34f06b1e2
Reporting entity
- Name
- Blade HQnorm: blade hq
- Domain
- bladehq.com
- Industry
- retail_consumer
Victim entity
- Name
- Blade HQnorm: blade hq
- Domain
- bladehq.com
- Industry
- retail_consumer
Incident
- Discovered
- Mar 22, 2021
- Materiality determined
- —
- Notification sent
- Apr 19, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- cooperate and follow the required protocols of applicable governmental authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 28d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 22, 2021→ Notified: Apr 19, 202128d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.