DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

Hourglass Cosmetics

bd_9f02648a5c413aea · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Feb 19, 2019

To disclose

Affected

44state residents only

Linked

4 filings

Confidence

67%
Full breach record for Hourglass Cosmetics

Hourglass Cosmetics notified New Hampshire AG of a data breach affecting 44 residents. Unauthorized third parties accessed customer data (names, addresses, credit card numbers, CCVs) from July 3, 2018 to January 30, 2019 via unauthorized access to the e-commerce checkout process. The company engaged forensic experts, removed malicious code, and notified law enforcement and its payment processor.

Incident timeline

Jul 3, 2018

Begins

Feb 19, 2019

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
California State AGFeb 15 · first
Massachusetts State AGFeb 15 · first
Montana State AGFeb 15 · first
New Hampshire State AG+4d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.