DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsCustomer Data InvolvedTargetedFinancial accountIdentity (basic)LowContained

GranQuartz

bd_d459dc0c18784e71 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jan 27, 2022

Filed

May 1, 2023

To disclose

15 months

Affected

4state residents only

Linked

4 filings

Confidence

66%
Full breach record for GranQuartz

GranQuartz, LP notified the New Hampshire AG of a data event affecting 4 NH residents. Unauthorized code was injected into the e-commerce website, allowing an actor to obtain customer checkout information (credit/debit card details) between Dec 29, 2022, and Jan 30, 2023. GranQuartz detected suspicious activity on Jan 27, 2022, engaged forensic specialists, and began notifying affected individuals on April 25, 2023.

Incident timeline

Dec 29, 2022

Begins

May 1, 2023

Filed

vs. sector median

+58 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Montana State AGApr 25 · first
Massachusetts State AGApr 25 · first
Maine State AGApr 25 · first
New Hampshire State AG+6d · this page

Pattern: first filing Apr 25 (MT), last May 1 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.