Bombas
bd_8eb047ffecafa64c · schema v1 · pii pii-v1
Full breach record for Bombas →4 incidents on fileBombas LLC notified customers of a historical data breach involving malicious code injection into its website between late 2014 and February 25, 2015. The incident potentially exposed names, addresses, and credit card information. Bombas identified the initial issue in early 2015 but re-examined the scope in 2018, leading to this supplemental notice for customers who made purchases between February 10 and February 25, 2015. The company has since migrated to a new e-commerce platform and implemented additional security measures. Free identity monitoring was offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 27, 2014
Begins
Feb 9, 2015
Discovered
Aug 31, 2018
Filed
vs. sector median
+178 wks slower
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- New Hampshire State AGbd_e86dfbd599fe370a2018-08-31Verified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.