Bombas
bd_a8afdb78c007e758 · schema v1 · pii pii-v1
Full breach record for Bombas →4 incidents on fileBombas, LLC disclosed a historical data breach affecting approximately 41,000 customers. Malware was identified in the code of a third-party e-commerce platform used for online sales between September 1, 2013, and February 9, 2015. The malware was initially removed on January 15, 2015. Affected data may include names, addresses, and credit card information. Bombas transitioned to a new e-commerce platform and offered two years of free identity monitoring through Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 1, 2013
Begins
Jan 15, 2015
Discovered
May 18, 2018
Filed
vs. sector median
+167 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_632c602d45662e4e2018-05-18Candidate
- New Hampshire State AGbd_7c07b8808eed98d92018-05-18Verified
- Oregon State AGbd_9ced2a7275ad71ad2018-05-18Verified
- Massachusetts State AGbd_f7abae59dfdafb742018-05-21 · +3dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.