HackingSkimmerStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Green Bay Packers – packers.com
bd_a742f8136d48612d · schema v1 · pii pii-v1
Full breach record for Green Bay Packers – packers.com →Green Bay Packers, Inc. disclosed a data breach affecting its Pro Shop website (packersproshop.com). On October 23, 2024, the organization detected malicious code inserted by a third-party threat actor. The code allowed unauthorized access to customer payment information, including credit card numbers and verification codes, entered during checkout between September 23-24 and October 3-23, 2024. The incident was contained by disabling checkout capabilities and removing the code. Affected individuals are offered 36 months of credit monitoring.
California clockDiscovered Oct 23, 2024 → Notified Jan 6, 202575d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1c79b4fb10fbe2b0New Hampshire State AGfiled 2025-01-06Verified
- bd_872a4fab4a12fc61Wisconsin State AGfiled 2025-01-06Verified
- bd_bb8d1110067d538eIndiana State AGfiled 2025-01-06Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-596987
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 6, 2025
- Raw hash
- 2655ad10aae23c9f46cb2f1d95deae7c68378a30b624d7305e5881d75f3f4108
Reporting entity
- Name
- Green Bay Packers – packers.comnorm: green bay packers packerscom
- Domain
- packers.com
Victim entity
- Name
- Green Bay Packers – packers.comnorm: green bay packers packerscom
- Domain
- packers.com
Incident
- Discovered
- Oct 23, 2024
- Materiality determined
- —
- Notification sent
- Jan 6, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Pro Shop website vendor
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- CA 60-day late · 75d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 23, 2024→ Notified: Jan 6, 202575d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.