DisclosureLens
MalwareRetail & ConsumerRetailRansomwareSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsMediumContained

Ballistic Products, Inc.

bd_cc0ec26377c09de6 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 1, 2022

Filed

Sep 3, 2022

To disclose

22 weeks

Affected

1,242state residents only

Linked

8 filings

Confidence

69%
Full breach record for Ballistic Products, Inc.

Ballistic Products, Inc. notified Washington AG of a third-party vendor malware incident affecting payment card data (names, card numbers, CVV, billing addresses) for transactions between Sept 2020 and Feb 2022. 1,242 WA residents notified in Sept 2022. Vendor removed malware and offered credit monitoring.

Washington clock WA AG >90d22 weeks discovery → filing

Incident timeline

undetected · 560 days
discovery → filing · 22 weeks / 155 days

Sep 18, 2020

Begins

Apr 1, 2022

Discovered

Sep 3, 2022

Filed

vs. sector median

+14 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 18d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing Sep 1 (IN), last Sep 21 (MA) — a 20-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.