MalwareRetail & ConsumerRetailSkimmerCapture App DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCILowResolved
Green Bay Packers
bd_9404a971ada4801d · schema v1 · pii pii-v1
Full breach record for Green Bay Packers →Green Bay Packers, Inc. reported a web skimmer incident on its packersproshop.com checkout page. Malicious code inserted by a third-party threat actor captured customer payment and personal information during purchases made between September 23–24 and October 3–23, 2024. Discovered December 20, 2024; 47 Maryland residents affected. Data potentially exposed includes names, addresses, email addresses, and full credit card details. Vendor-hosted site; GBP engaged cybersecurity experts and enhanced security protocols.
Maryland clock✗ MD AG >90d17 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed47 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376123.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 19, 2026
- Raw hash
- 3a29cd267f3e8bca2ae8f6e8d5ddb7ce190cc82c93cfbcd93962e6adf4c0b417
Reporting entity
- Name
- Green Bay Packersnorm: green bay packers
- Domain
- packersproshop.com
Victim entity
- Name
- Green Bay Packersnorm: green bay packers
- Domain
- packersproshop.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Dec 20, 2024
- Materiality determined
- —
- Notification sent
- Jan 6, 2025
- Affected individuals
- 47
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1059 Command and Scripting InterpreterT1056 Input CaptureT1074 Data Staged
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General pursuant to Md. Code Ann. Comm. Law 14-3504Notified three largest nationwide consumer reporting agencies including Equifax, Experian and TransUnion
- Initial access
- supply_chain
Compliance
- Time to disclose
- 17 months(515 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.