HackingRetail & ConsumerRetailCapture App DataData ExfiltratedCustomer Data InvolvedTargetedPCIPIILowContained
Hay House LLC
bd_bcfd340f3550e17d · schema v1 · pii pii-v1
Full breach record for Hay House LLC →Hay House LLC (hayhouse.com) discovered on December 5, 2024 that malicious code was injected into their website checkout page, capturing payment card data (cardholder name, card number, CVV, expiration date) from customers who transacted between August 3–5, 2024. 6,011 individuals were affected in total; 19 were Maine residents. The incident was classified as an external system breach (hacking). No identity theft protection services were offered.
Maine clockDiscovered Dec 5, 2024 → Filed with AG Dec 11, 20246d ✓ ME AG ≤30d6 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_d6bcf57fe408b215Vermont State AGfiled 2024-12-10(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/763292a2-225e-4edc-be88-0a8292a4459d.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 11, 2024
- Raw hash
- ae16ebb51566cb276134daa93083eeed33e25a6b6ea0919d871848f289af4e90
Reporting entity
- Name
- Hay House LLCnorm: hay house
- Domain
- hayhouse.com
- Industry
- Other Commercial
Victim entity
- Name
- Hay House LLCnorm: hay house
- Domain
- hayhouse.com
- Industry
- Other Commercial
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Dec 5, 2024
- Materiality determined
- —
- Notification sent
- Dec 11, 2024
- Affected individuals
- 19
- Data types
- PCIPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1185 Browser Session HijackingT1059 Command and Scripting Interpreter
- Threat actor
- ExternalFinancial
- Regulator citations
- Maine Attorney General notified
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 6d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 5, 2024→ Filed with AG: Dec 11, 20246d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.