Heirloom Roses
bd_c9b21be8111f06ec · schema v1 · pii pii-v1
Full breach record for Heirloom Roses →Heirloom Roses, a retail business, notified the Washington AG of a cyberattack where malicious code on its website captured customer names and credit card data. The incident occurred between Feb 12 and Oct 26, 2021, and was discovered on Aug 12, 2021. 3,118 Washington residents were affected. Heirloom engaged forensic specialists, removed the code, changed payment processors, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 12, 2021
Begins
Aug 12, 2021
Discovered
Dec 17, 2021
Filed
vs. sector median
+11 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Maine State AGbd_3c6bde4e9111e4832021-12-17Verified
- Oregon State AGbd_6534d6c864b8f2ca2021-12-17Verified
- California State AGbd_660ee01c3e82267e2021-12-17Verified
- Montana State AGbd_967abeb7c36a4e582021-12-17Verified
Show 4 more filings ↓Show fewer ↑up to 350d gap
- Massachusetts State AGbd_ddc8131d0fee95fd2021-12-17Verified
- Indiana State AGbd_f6f92f81ea61beb52021-12-17Verified
- New Hampshire State AGbd_51464c0d5acb01872021-12-23 · +6dVerified
- Illinois State AGbd_98e2cfac9ef7eece2021-01-01 · +350dCandidate
Filing propagation · 9 filings · 9 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Dec 23 (NH) — a 356-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.