Gettington
bd_a5699ba08cf4807d · schema v1 · pii pii-v1
Bluestem Brands, Inc. (via subsidiaries Gettington, Fingerhut, and PayCheck Direct) notified Montana residents of a data security incident where cyber-attackers attempted unauthorized access to customer accounts between March 24 and April 7, 2017. Accessed data included names, addresses, emails, phone numbers, and credit account numbers. Access was blocked and fraud holds placed.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 24, 2017
Begins
Apr 13, 2017
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- California State AGbd_d5010f50502fedc62017-04-13Verified
- New Hampshire State AGbd_dc31d724075bdd082017-04-13Verified
- Massachusetts State AGbd_674a80d32ecde53a2017-04-06 · +7dVerified
- New Hampshire State AGbd_c64d2e5efabfebe32017-05-08 · +25dVerified
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Apr 6 (MA), last May 8 (NH) — a 32-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.