Bombas
bd_9101cc153fd11ef1 · schema v1 · pii pii-v1
Full breach record for Bombas →4 incidents on fileBombas LLC discovered that malicious code designed to scrape payment card data and personal information may have been present on its e-commerce platform from November 11, 2016 to February 16, 2017. A security feature added in February 2017 stopped the code from functioning. An investigative report received May 20, 2020 could not rule out successful scraping of customer name, address, and payment card data. Customers were offered two years of identity monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 11, 2016
Begins
Jun 3, 2020
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Montana State AGbd_032c860efe4a2ff32020-06-03Candidate
- New Hampshire State AGbd_2e0f55b86f1170a32020-06-03Verified
- Oregon State AGbd_2f92b42d2848b3ab2020-06-03Verified
- Indiana State AGbd_9b29684e29b93fe12020-06-03Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- Washington State AGbd_f50804e00f8304562020-06-03Verified
- Massachusetts State AGbd_43c63091f0426d8f2020-06-04 · +1dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.