MalwareRetail & ConsumerRetailCapture App DataInfostealerCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTPIIPCILowResolved
Bombas, LLC
bd_9101cc153fd11ef1 · schema v1 · pii pii-v1
Full breach record for Bombas, LLC →Bombas LLC discovered that malicious code designed to scrape payment card data and personal information may have been present on its e-commerce platform from November 11, 2016 to February 16, 2017. A security feature added in February 2017 stopped the code from functioning. An investigative report received May 20, 2020 could not rule out successful scraping of customer name, address, and payment card data. Customers were offered two years of identity monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_032c860efe4a2ff3Montana State AGfiled 2020-06-03Candidate
- bd_2f92b42d2848b3abOregon State AGfiled 2020-06-03Verified
- bd_f50804e00f830456Washington State AGfiled 2020-06-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190612
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 3, 2020
- Raw hash
- 563a229c17b6848932c1dc4e2814be595ebc871e92625811da7d91bd1ab9a741
Reporting entity
- Name
- Bombas, LLCnorm: bombas
Victim entity
- Name
- Bombas, LLCnorm: bombas
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTPIIPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1056 Input CaptureT1185 Browser Session Hijacking
- Threat actor
- ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.