DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsTargetedData ExfiltratedPIIFinancial accountLowContained

Heirloom Roses

bd_967abeb7c36a4e58 · schema v1 · pii pii-v1

Severity

Low

Discovered

Aug 12, 2021

Filed

Dec 17, 2021

To disclose

18 weeks

Affected

210state residents only

Linked

9 filings

Confidence

65%
Full breach record for Heirloom Roses

Heirloom Roses notified affected individuals of a payment card skimming incident. Malicious code was added to the website between February and October 2021, capturing credit card data. The company engaged forensic specialists, removed the code, and offered 12 months of identity monitoring. Discovery was reported on August 12, 2021.

Incident timeline

undetected · 192 days
discovery → filing · 18 weeks / 127 days

Feb 1, 2021

Begins

Aug 12, 2021

Discovered

Dec 17, 2021

Filed

vs. sector median

+11 wks slower

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 350d gap

Filing propagation · 9 filings · 9 states

View merged incident ↗

Pattern: first filing Jan 1 (IL), last Dec 23 (NH) — a 356-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.