Bluestem Brands, Inc.
bd_c64d2e5efabfebe3 · schema v1 · pii pii-v1
Full breach record for Bluestem Brands, Inc. →2 incidents on fileBluestem Brands (Fingerhut/Gettington) filed a supplemental notice with NH AG regarding a data incident. Attackers used compromised credentials from third-party sites to access customer accounts between April 18-30, 2017. 11 NH residents affected. Data included names, addresses, emails, phone numbers, and credit account numbers. Bluestem blocked access, re-issued credit numbers, and notified customers.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 18, 2017
Begins
May 8, 2017
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_a5699ba08cf4807d2017-04-13 · +25dCandidate
- California State AGbd_d5010f50502fedc62017-04-13 · +25dVerified
- New Hampshire State AGbd_dc31d724075bdd082017-04-13 · +25dVerified
- Massachusetts State AGbd_674a80d32ecde53a2017-04-06 · +32dVerified
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Apr 6 (MA), last May 8 (NH) — a 32-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.