HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Golf & Ski Warehouse, Inc.
bd_d3f2d3f98affd7b0 · schema v1 · pii pii-v1
Full breach record for Golf & Ski Warehouse, Inc. →Golf & Ski Warehouse, Inc. notified consumers of a data breach involving its payroll vendor, Paycor. Paycor's MOVEit file transfer server was compromised, potentially exposing employee information including names and financial data. GSW systems were not impacted. The company is offering credit monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2177640ce200cc71Montana State AGfiled 2024-01-11Candidate
- bd_32f76a55ad442b67Maine State AGfiled 2024-01-23(12d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-01-11-golf-ski-warehouse-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 11, 2024
- Raw hash
- f52a3c18fdf342fcaae34aedec6bdf1e5175d5a868878512c9a3a4554eb1aaf9
Reporting entity
- Name
- Golf & Ski Warehouse, Inc.norm: golf ski warehouse
Victim entity
- Name
- Golf & Ski Warehouse, Inc.norm: golf ski warehouse
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jan 11, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Paycor
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.