The C.H. Hanson Company
bd_d1505662e1f60c46 · schema v1 · pii pii-v1
Full breach record for The C.H. Hanson Company →The C.H. Hanson Company notified customers that CommerceV3, its third-party e-commerce platform provider, experienced unauthorized access to its systems between Nov 24, 2021 and Dec 14, 2022. The incident potentially exposed cardholder data including names, emails, billing addresses, payment card numbers, CVVs, and expiration dates. CommerceV3 conducted a forensic investigation and implemented security measures; C.H. Hanson terminated the relationship and migrated platforms.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2021
Begins
May 3, 2023
Discovered
Oct 20, 2023
Filed
vs. sector median
+17 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Indiana State AGbd_7f3cdc920ce3aa342023-10-19 · +1dVerified
- Massachusetts State AGbd_e02e33c5d043168b2023-10-30 · +10dVerified
- New Hampshire State AGbd_73f4f18616a9e8e12023-11-01 · +12dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Oct 19 (IN), last Nov 1 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.