HackingSkimmerCapture Stored DataCustomer Data InvolvedData ExfiltratedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Outdoor Smart! Inc
bd_c828eb1df170a599 · schema v1 · pii pii-v1
Full breach record for Outdoor Smart! Inc →OutdoorSmart! Inc. disclosed a security incident affecting its Campfire Collective website. Unauthorized code capable of capturing payment card information was present between February 15, 2024, and November 4, 2025. The company detected unusual activity on November 3, 2025, and removed the code the following day. Affected data includes names and payment card details (card number, expiration, CVC). The company is offering 24 months of credit monitoring and identity restoration services.
California clockDiscovered Nov 3, 2025 → Notified Dec 4, 202531d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3168f9850d26a5b3Washington State AGfiled 2025-12-19Candidate
- bd_6c6eccc5335561c3Maine State AGfiled 2025-12-19Verified
- bd_e9416fffa56fe7ebVermont State AGfiled 2025-12-19Verified
- bd_fe40f045ec9e37c2Indiana State AGfiled 2025-12-19Verified
Show 2 more filings ↓Show fewer ↑up to 19d gap
- bd_f53a3a1268dc51f0New Hampshire State AGfiled 2025-12-22(3d gap)Verified
- bd_8e546bbf2f313013Texas State AGfiled 2026-01-07(19d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-616038
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2025
- Raw hash
- 685b223a7ab3616450142503fccc60547dbf7cc3b031cd9971cd652cb27f9657
Reporting entity
- Name
- Outdoor Smart! Incnorm: outdoor smart
Victim entity
- Name
- Outdoor Smart! Incnorm: outdoor smart
Incident
- Discovered
- Nov 3, 2025
- Materiality determined
- —
- Notification sent
- Dec 4, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 31d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 3, 2025→ Notified: Dec 4, 202531d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.