HackingVulnerability ExploitStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
SelectBlinds
bd_8c0eda7f606a2408 · schema v1 · pii pii-v1
Full breach record for SelectBlinds →SelectBlinds notified consumers of a data breach where malware embedded on its website scraped transaction data from January 7, 2024, through September 28, 2024. Affected data included names, addresses, payment card details (including CVV), and credentials. SelectBlinds engaged external experts, contained the incident, and locked user accounts. No specific total affected count was disclosed in the filing.
Vermont clock⏱ VT AG >14 bday4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_1923f9007672926fMaine State AGfiled 2024-10-31(2d gap)Verified
- bd_1af605e003eeaadeVermont State AGfiled 2024-10-31(2d gap)Verified
- bd_302d1ff6caa823bcDelaware State AGfiled 2024-10-31(2d gap)Candidate
- bd_3d0c0642d4dc639aMontana State AGfiled 2024-10-31(2d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 22d gap
- bd_41a17bd100035b7fIndiana State AGfiled 2024-10-31(2d gap)Verified
- bd_7dfc75746b157d31New Hampshire State AGfiled 2024-10-31(2d gap)Verified
- bd_7ed9e87de0e792e1California State AGfiled 2024-10-31(2d gap)Verified
- bd_dd07d60af013eeadOregon State AGfiled 2024-10-31(2d gap)Verified
- bd_e041a012af34a2d7Washington State AGfiled 2024-10-31(2d gap)Verified
- bd_8a9d4c7ca3c46cc5Delaware State AGfiled 2024-10-07(22d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-10-29-selectblinds-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 29, 2024
- Raw hash
- b32adcebc5db77214b68e76ced0d458b7235b72c45e72300e12322a4d9fbe7ae
Reporting entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Victim entity
- Name
- SelectBlindsnorm: selectblinds
- Domain
- selectblinds.com
Incident
- Discovered
- Sep 28, 2024
- Materiality determined
- —
- Notification sent
- Oct 31, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.