DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Financial accountLowResolved

Bombas

bd_8eb047ffecafa64c · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 9, 2015

Filed

Aug 31, 2018

To disclose

43 months

Affected

Not disclosed

Linked

2 filings

Confidence

64%
Full breach record for Bombas4 incidents on file

Bombas LLC notified customers of a historical data breach involving malicious code injection into its website between late 2014 and February 25, 2015. The incident potentially exposed names, addresses, and credit card information. Bombas identified the initial issue in early 2015 but re-examined the scope in 2018, leading to this supplemental notice for customers who made purchases between February 10 and February 25, 2015. The company has since migrated to a new e-commerce platform and implemented additional security measures. Free identity monitoring was offered to affected individuals.

California clockDiscovered Feb 9, 2015Notified Nov 29, 20181389d CA 60-day late43 months discovery → filing

Incident timeline

undetected · 135 days
discovery → filing · 43 months / 1299 days

Sep 27, 2014

Begins

Feb 9, 2015

Discovered

Aug 31, 2018

Filed

vs. sector median

+178 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGAug 31 · first
California State AGAug 31 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.