HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Vermont Christmas Company
bd_bbb64d7a974fdbe5 · schema v1 · pii pii-v1
Full breach record for Vermont Christmas Company →Vermont Christmas Company notified customers of unauthorized access to its third-party vendor, CommerceV3, between Nov 24, 2021, and Dec 14, 2022. Potentially impacted data includes name, billing address, email, payment card number, CVV, and expiration date. The company is reviewing vendor procedures and notifying regulators.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1627e564dd024a85Vermont State AGfiled 2023-08-09Verified
- bd_c56e39394fec7748New Hampshire State AGfiled 2023-08-09Verified
- bd_e2882215251a929bMaine State AGfiled 2023-08-09Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571554
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2023
- Raw hash
- c25456c393b54133caf5a64511592a07c033c027d4b4eba7d04bd688d2c1d1c4
Reporting entity
- Name
- Vermont Christmas Companynorm: vermont christmas
- Domain
- vermontchristmasco.com
Victim entity
- Name
- Vermont Christmas Companynorm: vermont christmas
- Domain
- vermontchristmasco.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Aug 9, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notifying relevant regulatory authorities
- Third party
- via CommerceV3
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.