DisclosureLens
FEDERALItem 8.01 · voluntaryHackingRetail & ConsumerRetailData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsMediumResolved

Polished.com

bd_98c4b857a36d4e67 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

May 26, 2023

To disclose

Affected

9,290

Linked

8 filings

Confidence

68%
Full breach record for Polished.com

Polished.com Inc. disclosed a hacking attack on its e-commerce checkout page on March 16, 2023. Personal information (names, addresses, zip codes) and payment card data (numbers, expiration dates, CVVs) was extracted from the Company's systems; out of an abundance of caution the Company notified approximately 9,290 individuals as of May 24, 2023. The company deployed containment measures, engaged third-party experts, and notified law enforcement. The matter is considered remediated.

Incident timeline

Mar 16, 2023

Begins

May 26, 2023

Filed

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 4d gap

Filing propagation · 8 filings · 7 states

View merged incident ↗
Maine State AGMay 22 · first
Montana State AGMay 22 · first
Vermont State AGMay 22 · first
California State AGMay 22 · first
Massachusetts State AGMay 22 · first
Indiana State AGMay 22 · first
New Hampshire State AGMay 22 · first
SEC 8-K+4d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.