HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
ZAGG INC
bd_8bfeb775d88b1faa · schema v1 · pii pii-v1
Full breach record for ZAGG INC →ZAGG Inc. notified the NH AG of a data event involving its e-commerce platform provider BigCommerce. A third-party app (FreshClick) was compromised, injecting malicious code to scrape credit card data from customer transactions between Oct 26 and Nov 7, 2024. ZAGG detected the issue on Nov 8, 2024, secured the site, and offered credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2897d5f1410fd4c7Vermont State AGfiled 2024-12-26Verified
- bd_2d4f1c766ccd3c72Montana State AGfiled 2024-12-26Candidate
- bd_6c96b075c8ba3b8dIndiana State AGfiled 2024-12-26Verified
- bd_745e0f485ef3b1f7Maine State AGfiled 2024-12-26Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/zagg-20241226.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 26, 2024
- Raw hash
- 6759c774a44f498e5d59640e83c48c978bf7a39e5de454b0bcff2a16166384d4
Reporting entity
- Name
- ZAGG INCnorm: zagg
Victim entity
- Name
- ZAGG INCnorm: zagg
Incident
- Discovered
- Nov 8, 2024
- Materiality determined
- Nov 21, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.