DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedTargetedIdentity (basic)Financial accountFinancial credentialsLowContained

Active Lifestyle Products & Services, Inc

bd_9931ba86ec02c7e6 · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 25, 2021

Filed

Apr 5, 2021

To disclose

6 weeks

Affected

100state residents only

Linked

4 filings

Confidence

66%
Full breach record for Active Lifestyle Products & Services, Inc2 incidents on file

Active Lifestyle Products & Services, Inc. (ALPS) notified customers of a data breach where an unknown third party installed malicious software on its e-commerce websites between April 2020 and February 2025. The malware captured credit card numbers, expiration dates, CVVs, names, addresses, and emails. ALPS disabled affected systems, engaged forensic investigators, and secured its technology. No SSNs or PHI were involved.

Incident timeline

undetected · 311 days
discovery → filing · 6 weeks / 39 days

Apr 20, 2020

Begins

Feb 25, 2021

Discovered

Apr 5, 2021

Filed

vs. sector median

2 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Maine State AGMar 24 · first
Montana State AG+12d · this page

Pattern: first filing Mar 24 (ME), last Apr 7 (MA) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.