DisclosureLens
HackingManufacturingRetail & ConsumerManufacturingVulnerability ExploitStolen CredentialsZero-DayData ExfiltratedCustomer Data InvolvedFinancial accountIdentity (basic)LowContained

SMOOTH-ON, INC.

bd_cdf0c2f83dc934eb · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 29, 2019

Filed

May 21, 2019

To disclose

22 days

Affected

Not disclosed

Confidence

64%
Full breach record for SMOOTH-ON, INC.

Smooth-On, Inc. notified New Hampshire of a data breach affecting customers who made purchases between Feb 24 and Apr 29, 2019. A hacker injected malicious code into the Magento ecommerce platform, potentially stealing credit card numbers, expiration dates, security codes, and billing addresses. The company suspended online ordering, engaged Sucuri and Carbonlogic for forensic investigation, and notified affected customers on May 9, 2019. Exact number of affected individuals is unknown as card data is not stored on servers.

Incident timeline

undetected · 64 days
discovery → filing · 22 days

Feb 24, 2019

Begins

Apr 29, 2019

Discovered

May 21, 2019

Filed

vs. sector median

8 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.