MalwareRansomwareData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
Bombas, LLC
bd_a8afdb78c007e758 · schema v1 · pii pii-v1
Full breach record for Bombas, LLC →Bombas, LLC reported a data breach involving malware embedded in its third-party e-commerce platform. The malware existed from September 1, 2013, until February 9, 2015, potentially affecting approximately 41,000 customers who made credit card purchases. The incident exposed names, addresses, and credit card information. Bombas engaged Kroll to provide two years of free identity monitoring and transitioned to a new e-commerce platform.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_632c602d45662e4eMontana State AGfiled 2018-05-18Candidate
- bd_9ced2a7275ad71adOregon State AGfiled 2018-05-18Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136345
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2018
- Raw hash
- 54236ace50d2dee2a14cdd80c0d10e728206b22d76312c630777b9bedf0e5daf
Reporting entity
- Name
- Bombas, LLCnorm: bombas
Victim entity
- Name
- Bombas, LLCnorm: bombas
Incident
- Discovered
- Jan 15, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 41,000
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 41 months(1219 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.