HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Blade HQ
bd_bf35a6f255d2a15b · schema v1 · pii pii-v1
Full breach record for Blade HQ →Blade HQ, a commercial entity based in Pleasant Grove, UT, reported an external system breach (hacking) occurring between January 7, 2021, and April 11, 2021. The breach was discovered on March 22, 2021, and affected approximately 90,000 individuals, including 557 Maine residents. Compromised data included names and financial account or credit/debit card numbers (with security codes/PINs). Written notification was sent on April 30, 2021. No identity theft protection services were offered.
Maine clockDiscovered Mar 22, 2021 → Filed with AG Apr 20, 202129d ✓ ME AG ≤30d29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_a449fbb90cda4b3eMontana State AGfiled 2021-04-20Verified
- bd_4de597f4ac5ffcf4Oregon State AGfiled 2021-04-19(1d gap)Candidate
- bd_8a34f4aeb2a21f7eCalifornia State AGfiled 2021-04-19(1d gap)Verified
- bd_981135236a66aab2Washington State AGfiled 2021-04-19(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1ef92b92-ae76-4cd1-bd9b-bb120b04b1b5.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 20, 2021
- Raw hash
- 44e0ff40387174733906688db06e87ab6dfcb6e2ae362d7986761de358bbced7
Reporting entity
- Name
- Blade HQnorm: blade hq
- Domain
- bladehq.com
Victim entity
- Name
- Blade HQnorm: blade hq
- Domain
- bladehq.com
Incident
- Discovered
- Mar 22, 2021
- Materiality determined
- —
- Notification sent
- Apr 30, 2021
- Affected individuals
- 90,000
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 29d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 22, 2021→ Filed with AG: Apr 20, 202129d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.