HackingFINANCIAL_ACCOUNTPIILowContained
Nuna Baby Essentials, Inc.
bd_c4723f4f3e920095 · schema v1 · pii pii-v1
Full breach record for Nuna Baby Essentials, Inc. →Nuna Baby Essentials, Inc. notified New Hampshire residents of a cybersecurity incident where malicious code was installed on its website from March 26, 2020, to April 7, 2021. The code potentially compromised payment card information (number, expiration, CVV, billing/shipping addresses). Nuna discovered the incident on December 22, 2021, and reported it to law enforcement. The company offered one year of free identity protection services through Experian to affected customers.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_18f9ad3ae70ad7ecOregon State AGfiled 2022-01-21Candidate
- bd_4eafc4fff2bb621eMontana State AGfiled 2022-01-21Verified
- bd_bb40bd92db0b3ff5Washington State AGfiled 2022-01-21Verified
- bd_c649cf3bb776e5a7Maine State AGfiled 2022-01-21Verified
Show 1 more filing ↓Show fewer ↑
- bd_ccd03f2f0730db36California State AGfiled 2022-01-21Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nuna-baby-essentials-20220121.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 21, 2022
- Raw hash
- 3a776b53491cfe9e38c587c1412ec8c5a6ee966857591e9cd902ff2dd2c8f072
Reporting entity
- Name
- Nuna Baby Essentials, Inc.norm: nuna baby essentials
- Domain
- nunalife.com
Victim entity
- Name
- Nuna Baby Essentials, Inc.norm: nuna baby essentials
- Domain
- nunalife.com
Incident
- Discovered
- Dec 22, 2021
- Materiality determined
- —
- Notification sent
- Jan 21, 2022
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.