HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
MarketPlace: Handwork of India
bd_92faa74eccb78f02 · schema v1 · pii pii-v1
Full breach record for MarketPlace: Handwork of India →MarketPlace Handwork of India notified customers of a data breach involving its third-party e-commerce platform, CommerceV3. An unauthorized party accessed CommerceV3 systems between November 24, 2021, and December 14, 2022. MarketPlace India was notified on June 6, 2023. Affected data may include names, email addresses, billing addresses, payment card numbers, expiration dates, and security codes. The company implemented additional security measures and offered 12 months of credit monitoring.
California clockDiscovered Jun 6, 2023 → Notified Sep 11, 202397d ✗ CA 60-day late14 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_0b6401102608e455Vermont State AGfiled 2023-09-11(1d gap)Verified
- bd_d42937317e38b72aOregon State AGfiled 2023-09-11(1d gap)Candidate
- bd_fb18a94c3350429bMaine State AGfiled 2023-09-11(1d gap)Verified
- bd_02484d172a074742New Hampshire State AGfiled 2023-09-18(6d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-573126
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 12, 2023
- Raw hash
- 6e1831d77b4e6f58282f8b8c9f031bad35a72422d5e949f89d743e497f13297e
Reporting entity
- Name
- MarketPlace: Handwork of Indianorm: marketplace handwork of india
Victim entity
- Name
- MarketPlace: Handwork of Indianorm: marketplace handwork of india
Incident
- Discovered
- Jun 6, 2023
- Materiality determined
- —
- Notification sent
- Sep 11, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via CommerceV3
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- CA 60-day late · 97d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 6, 2023→ Notified: Sep 11, 202397d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.