MalwareRansomwareData ExfiltratedSupply Chain (3P Vendor)FINANCIAL_ACCOUNTPIILowContained
Burnt Ridge Nursery and Orchards, Inc.
bd_b210d820b631ed03 · schema v1 · pii pii-v1
Full breach record for Burnt Ridge Nursery and Orchards, Inc. →Burnt Ridge Nursery and Orchards, Inc. disclosed a data security incident involving malware on a third-party e-commerce vendor's server. The malware captured payment card information (cardholder name, number, security code, expiration date) for customers who made purchases between September 18, 2020, and February 3, 2022. The vendor identified the malware in early February 2022, removed it, engaged forensic experts, and notified federal law enforcement and payment card companies. The incident is contained.
California clockDiscovered Feb 1, 2022 → Notified Feb 3, 20222d ✓ CA 60-day OK28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6680e75414dd1a20Maine State AGfiled 2022-08-16Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556293
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 16, 2022
- Raw hash
- e8e8b803e2bfc7ef67ae8911c208833b8358286422bb4b5910ed7938ae3d8ae5
Reporting entity
- Name
- Burnt Ridge Nursery and Orchards, Inc.norm: burnt ridge nursery and orchards
- Domain
- burntridgenursery.com
Victim entity
- Name
- Burnt Ridge Nursery and Orchards, Inc.norm: burnt ridge nursery and orchards
- Domain
- burntridgenursery.com
Incident
- Discovered
- Feb 1, 2022
- Materiality determined
- —
- Notification sent
- Feb 3, 2022
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 28 weeks(196 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 2d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 1, 2022→ Notified: Feb 3, 20222d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.