HackingVulnerability ExploitData ExfiltratedTargetedPIIFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Bodyartforms LLC
bd_b92497a57f4e63a6 · schema v1 · pii pii-v1
Full breach record for Bodyartforms LLC →Bodyartforms LLC notified consumers of a data breach where payment card information (name, billing address, card number, security code) was captured via its website checkout page between October 16, 2023, and March 7, 2024. The company engaged third-party cybersecurity specialists, reset passwords, enhanced firewall security, and reviewed website code. No specific affected individual count was disclosed in the filing.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_1a4de5a5cc6c207bOregon State AGfiled 2024-05-08Candidate
- bd_22d842bdc6144ed3Maine State AGfiled 2024-05-08Verified
- bd_33bdadd8b9e28727California State AGfiled 2024-05-08Verified
- bd_3f0084a4cac482f2Washington State AGfiled 2024-05-08Verified
Show 3 more filings ↓Show fewer ↑
- bd_50ec5dd6953229d7Indiana State AGfiled 2024-05-08Verified
- bd_6991ab0c1e0b410eMontana State AGfiled 2024-05-08Verified by operator
- bd_cc8f9158c57ebb20New Hampshire State AGfiled 2024-05-08Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-08-bodyartforms-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 8, 2024
- Raw hash
- 02603cdf0d9b66c223a11571494f6019b0d0b113edcbf5bc923a9149ca8ac07d
Reporting entity
- Name
- Bodyartforms LLCnorm: bodyartforms
- Domain
- bodyartforms.com
Victim entity
- Name
- Bodyartforms LLCnorm: bodyartforms
- Domain
- bodyartforms.com
Incident
- Discovered
- Mar 7, 2024
- Materiality determined
- —
- Notification sent
- May 8, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notifying applicable regulatory authorities and consumer reporting agencies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.