HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
Bavaria Sausage
bd_8e09e118070e3ddc · schema v1 · pii pii-v1
Full breach record for Bavaria Sausage →Bavaria Sausage, Inc. notified the Maryland Attorney General of a data event affecting approximately 117 Maryland residents. The incident involved unauthorized access to payment card information (numbers, expiration, security codes) and names via the company's online store (bavariasausage.com) between April 6, 2024, and January 17, 2025. The company engaged forensic investigators, notified credit bureaus, and provided identity resolution services through TransUnion.
Maryland clock⏱ MD AG >30d9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_8c204176c20f448eMontana State AGfiled 2025-03-03Candidate
- bd_a2e695d6c6447e90Indiana State AGfiled 2025-03-03Verified
- bd_bcdf3997d69929dbNew Hampshire State AGfiled 2025-03-03Verified
- bd_1e26b8d1523f5ac6Vermont State AGfiled 2025-03-04(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 4d gap
- bd_51b0c8458e17c904Maine State AGfiled 2025-03-07(4d gap)Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376473.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 3, 2025
- Raw hash
- b89dc46966d727fc14d46d5d6b36b6aff55122e1085d2ab87f0448ecbdc01075
Reporting entity
- Name
- Bavaria Sausagenorm: bavaria sausage
- Domain
- bavariasausage.com
Victim entity
- Name
- Bavaria Sausagenorm: bavaria sausage
- Domain
- bavariasausage.com
Incident
- Discovered
- Jan 1, 2025
- Materiality determined
- —
- Notification sent
- Mar 3, 2025
- Affected individuals
- 117
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.