DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCustomer Data InvolvedData ExfiltratedIdentity (basic)Financial accountLowContained

Rainier Arms

bd_c12823e14182c7ab · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 1, 2021

Filed

Jun 2, 2022

To disclose

26 weeks

Affected

Not disclosed

Linked

8 filings

Confidence

66%
Full breach record for Rainier Arms2 incidents on file

Rainier Arms disclosed that malicious code on its website allowed an unauthorized party to access payment card information (names and credit/debit card numbers) for customers who made purchases between June 1, 2021, and January 19, 2022. The company identified the malicious code in December 2021 and confirmed the breach scope on April 21, 2022. Response actions included removing the code, engaging a cybersecurity firm, resetting passwords, and implementing additional security safeguards.

Incident timeline

undetected · 183 days
discovery → filing · 26 weeks / 183 days

Jun 1, 2021

Begins

Dec 1, 2021

Discovered

Jun 2, 2022

Filed

vs. sector median

+19 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filings

Filing propagation · 8 filings · 8 states

View merged incident ↗
Maine State AGJun 2 · first
Oregon State AGJun 2 · first
Montana State AGJun 2 · first
Washington State AGJun 2 · first
Indiana State AGJun 2 · first
California State AGJun 2 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.