FEDERALItem 8.01 · voluntaryHackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumResolved
Polished.com
bd_98c4b857a36d4e67 · schema v1 · pii pii-v1
Full breach record for Polished.com →Polished.com Inc. disclosed a hacking attack on March 16, 2023, impacting its e-commerce checkout page. Attackers extracted personal information (names, addresses, zip codes) and payment card data (numbers, expiration dates, CVVs). The company notified approximately 9,290 individuals and law enforcement. The incident is considered remediated.
SEC clockMateriality determined May 26, 2023 → Filed May 26, 20230d ✓ SEC 4-day OK10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_243ab28b57b1b35eMaine State AGfiled 2023-05-22(4d gap)Candidate
- bd_254a757d8efec848Montana State AGfiled 2023-05-22(4d gap)Verified
- bd_b871552b83ee6c52California State AGfiled 2023-05-22(4d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1810140/000121390023043529/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 26, 2023
- Raw hash
- f4c4355540c7cb0c593e632a59e63e5f0d08159ac0cf170949000c90c55f8f8b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Polished.comnorm: polishedcom
- SEC CIK
- 0001810140
- Domain
- polished.com
Victim entity
- Name
- Polished.comnorm: polishedcom
- SEC CIK
- 0001810140
- Domain
- polished.com
Incident
- Discovered
- Mar 16, 2023
- Materiality determined
- May 26, 2023
- Notification sent
- May 24, 2023
- Affected individuals
- 9,290
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- provided appropriate notice to regulatory authorities in accordance with applicable law
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: May 26, 2023→ Filed: May 26, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.