DisclosureLens
MalwareRetail & ConsumerRetailInfostealerSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIdentity (basic)Financial accountMediumResolved

Bombas

bd_a8afdb78c007e758 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 15, 2015

Filed

May 18, 2018

To disclose

41 months

Affected

41,000

Linked

5 filings

Confidence

65%
Full breach record for Bombas4 incidents on file

Bombas, LLC disclosed a historical data breach affecting approximately 41,000 customers. Malware was identified in the code of a third-party e-commerce platform used for online sales between September 1, 2013, and February 9, 2015. The malware was initially removed on January 15, 2015. Affected data may include names, addresses, and credit card information. Bombas transitioned to a new e-commerce platform and offered two years of free identity monitoring through Kroll.

California clockDiscovered Jan 15, 2015Notified Aug 24, 20181317d CA 60-day late41 months discovery → filing

Incident timeline

undetected · 501 days
discovery → filing · 41 months / 1219 days

Sep 1, 2013

Begins

Jan 15, 2015

Discovered

May 18, 2018

Filed

vs. sector median

+167 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Montana State AGMay 18 · first
New Hampshire State AGMay 18 · first
Oregon State AGMay 18 · first
California State AGMay 18 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.