OXO International Ltd.
bd_b5855d52ca392d1e · schema v1 · pii pii-v1
Full breach record for OXO International Ltd. →OXO International, Ltd. disclosed that unauthorized code on its e-commerce website may have compromised customer personal information, including names, addresses, and credit card details. The incident affected orders placed between June 2017 and October 2018. OXO confirmed the breach on December 17, 2018, after forensic investigation. The company removed the malicious code, conducted penetration testing, and offered one year of identity monitoring through Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 9, 2017
Begins
Dec 17, 2018
Discovered
Jan 3, 2019
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_4c6fa60d8da1d1e72018-12-28 · +6dCandidate
- New Hampshire State AGMagecartbd_4ffe12b67cda62a82018-12-28 · +6dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Dec 28 (MT), last Jan 3 (CA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.