HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Bombas, LLC
bd_8eb047ffecafa64c · schema v1 · pii pii-v1
Full breach record for Bombas, LLC →Bombas LLC reported a historical data breach involving malicious code injected into its e-commerce website between September 2014 and February 2015. The incident potentially exposed customer names, addresses, and credit card information for purchases made between February 10 and February 25, 2015. Bombas engaged Kroll to provide two years of free identity monitoring and migrated to a new e-commerce platform.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-139516
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 31, 2018
- Raw hash
- 7019e3ca8a27a716c09c423efae86d6524b47129d5f8490e990d555834d8ae1f
Reporting entity
- Name
- Bombas, LLCnorm: bombas
Victim entity
- Name
- Bombas, LLCnorm: bombas
Incident
- Discovered
- Feb 9, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 43 months(1299 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.