HackingVulnerability ExploitData ExfiltratedTargetedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
5.11, Inc
bd_d4546feba8b6348e · schema v1 · pii pii-v1
Full breach record for 5.11, Inc →5.11 notified Vermont AG on 2024-10-04 of a data breach affecting customers who purchased from 511tactical.com between July 12 and August 22, 2024. The incident involved unauthorized access to payment card information, names, and emails. 5.11 engaged forensic investigators, notified law enforcement and card brands, and is offering credit monitoring services.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_4f9fc1d533ca6b72Indiana State AGfiled 2024-10-04Verified
- bd_bd3adc8660ef9facMontana State AGfiled 2024-10-04Candidate
- bd_26c0478bb272bd4eOregon State AGfiled 2024-10-05(1d gap)Verified
- bd_2c151da7f96a559bMaine State AGfiled 2024-10-05(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_6899f0e1993e67d5Washington State AGfiled 2024-10-05(1d gap)Verified
- bd_c2a90fe02a449cc7California State AGfiled 2024-10-05(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-10-04-511-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 4, 2024
- Raw hash
- a83bca551edb8804d503c7d9fb49c21c3aea2339b92114ff6686c4d168af2541
Reporting entity
- Name
- 5.11, Incnorm: 511
- Domain
- 511tactical.com
Victim entity
- Name
- 5.11, Incnorm: 511
- Domain
- 511tactical.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- Oct 3, 2024
- Notification sent
- Oct 3, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the matter to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.