HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
HRM Enterprises, Inc.
bd_94fb78a9de5c5ab7 · schema v1 · pii pii-v1
Full breach record for HRM Enterprises, Inc. →HRM Enterprises, Inc. notified customers that its e-commerce provider, CommerceV3, suffered an unauthorized access incident between Nov 24, 2021, and Dec 14, 2022. Payment card information (name, card number, CVV, expiration, billing address, email) was potentially accessed. HRM was notified on June 8, 2023. The company is reviewing vendor requirements and policies.
California clockDiscovered Jun 8, 2023 → Notified Jul 26, 202348d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_08ea0397a9df9196Washington State AGfiled 2023-07-26Candidate
- bd_a134805f0dacc9b6Vermont State AGfiled 2023-07-26Verified
- bd_a81a49dc0137c4afMaine State AGfiled 2023-07-26Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570884
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2023
- Raw hash
- 913e00d8368ff14c04d13f64785917c8414d721606fdac30da35048514a5b16d
Reporting entity
- Name
- HRM Enterprises, Inc.norm: hrm enterprises
Victim entity
- Name
- HRM Enterprises, Inc.norm: hrm enterprises
Incident
- Discovered
- Jun 8, 2023
- Materiality determined
- —
- Notification sent
- Jul 26, 2023
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via CommerceV3
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 48d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 8, 2023→ Notified: Jul 26, 202348d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.