Roots & Harvest Direct LLC
bd_cbec415dc44f19ab · schema v1 · pii pii-v1
Full breach record for Roots & Harvest Direct LLC →Roots & Harvest Direct LLC reported a data breach affecting 26 Maine residents after a cybersecurity incident at its third-party e-commerce vendor, CommerceV3. The incident occurred between November 24, 2021, and December 14, 2022, and was discovered on June 6, 2023. The compromised data includes names and financial account or credit/debit card numbers, along with security codes, access codes, or passwords.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2021
Begins
Jun 6, 2023
Discovered
Jul 14, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_0254195321496ea82023-07-13 · +1dVerified
- New Hampshire State AGbd_2ce5ac206fc610092023-07-13 · +1dVerified
- Montana State AGbd_50caf27259718c062023-07-13 · +1dCandidate
- Indiana State AGbd_7a3b00926d3f02aa2023-07-06 · +8dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 6 (IN), last Jul 14 (ME) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.