DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

Letter Arts Book Club, Inc.

bd_a10a2f42526fa7ea · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Jul 7, 2023

To disclose

Affected

21state residents only

Confidence

66%

Letter Arts Book Club, Inc. (d/b/a John Neal Books) notified customers that their third-party e-commerce provider, CommerceV3, was breached. Unauthorized access occurred between Nov 24, 2021 and Dec 14, 2022. Compromised data included names, addresses, email, and payment card details (number, CVV, expiry). The company migrated to a new platform in Feb 2023.

Incident timeline

Nov 24, 2021

Begins

Jul 7, 2023

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed21 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.