HackingVulnerability ExploitCapture Stored DataData ExfiltratedTargetedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALSLowContained
SelectBlinds
bd_8a9d4c7ca3c46cc5 · schema v1 · pii pii-v1
Full breach record for SelectBlinds →SelectBlinds notified affected individuals of a data breach where malware was embedded on its website starting January 7, 2024, allowing unauthorized scraping of checkout data. The incident was discovered on September 28, 2024. Compromised data included names, addresses, phone numbers, and payment card details (including CVV). SelectBlinds contained the incident, engaged external experts, and locked user accounts.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_8c0eda7f606a2408Vermont State AGfiled 2024-10-29(22d gap)Candidate
- bd_1923f9007672926fMaine State AGfiled 2024-10-31(24d gap)Verified
- bd_1af605e003eeaadeVermont State AGfiled 2024-10-31(24d gap)Verified
- bd_302d1ff6caa823bcDelaware State AGfiled 2024-10-31(24d gap)Candidate
Show 6 more filings ↓Show fewer ↑up to 24d gap
- bd_3d0c0642d4dc639aMontana State AGfiled 2024-10-31(24d gap)Verified
- bd_41a17bd100035b7fIndiana State AGfiled 2024-10-31(24d gap)Verified
- bd_7dfc75746b157d31New Hampshire State AGfiled 2024-10-31(24d gap)Verified
- bd_7ed9e87de0e792e1California State AGfiled 2024-10-31(24d gap)Verified
- bd_dd07d60af013eeadOregon State AGfiled 2024-10-31(24d gap)Verified
- bd_e041a012af34a2d7Washington State AGfiled 2024-10-31(24d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/11/Notification-Samples.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 7, 2024
- Raw hash
- f28afcf079348d445864efb1624a48bc385b71d82ed9a0eeac0fd62af4944724
Reporting entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Victim entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Incident
- Discovered
- Sep 28, 2024
- Materiality determined
- —
- Notification sent
- Oct 31, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.