HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIFINANCIAL_ACCOUNTMediumContained
Louis Garneau Sports Inc.
bd_a5b2686ef00e8fe7 · schema v1 · pii pii-v1
Full breach record for Louis Garneau Sports Inc. →Louis Garneau Sports Inc. notified the New Hampshire Attorney General of a security breach involving its e-commerce website. Malicious code skimming customer checkout data was present from June 8 to July 28, 2023. The incident was discovered on July 26, 2023, following a law enforcement notice. Unauthorized exfiltration of personal and financial information occurred, affecting 2,966 individuals (18 in NH). The company engaged forensic experts, reset credentials, and provided credit monitoring services.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_59e420874e83fdf0Delaware State AGfiled 2023-08-28Candidate
- bd_9d888f34d2b16ef3Montana State AGfiled 2023-08-28Candidate
- bd_9ead43bf483feffaMaine State AGfiled 2023-08-28Verified
- bd_d29120276de1754cDelaware State AGfiled 2023-07-26(33d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/louis-garneau-sports-20230828.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2023
- Raw hash
- 44031974149f158fcbc191b9f1b2a284a4450f4de48e32aa14f910e5f85dbb65
Reporting entity
- Name
- Henrinorm: henri
- Domain
- welcome.henrihome.com
Victim entity
- Name
- Louis Garneau Sports Inc.norm: louis garneau sports-ca
Incident
- Discovered
- Jul 26, 2023
- Materiality determined
- —
- Notification sent
- Aug 28, 2023
- Affected individuals
- 2,966
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General – Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.