HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
CommerceV3
bd_d4b9b5ed6965643e · schema v1 · pii pii-v1
Full breach record for CommerceV3 →Creedmoor Sports, Inc. notified consumers that its third-party e-commerce provider, CommerceV3, Inc., experienced a data security incident. An unauthorized party accessed CommerceV3's systems between November 24, 2021, and December 14, 2022. The breach potentially exposed customer names, email addresses, billing addresses, payment card numbers, CVV codes, and expiration dates. Creedmoor engaged forensic experts and is offering 12 months of free credit monitoring and fraud assistance to affected individuals.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_45b7700712f9b85eCalifornia State AGfiled 2023-07-21Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-21-creedmoor-sports-commercev3-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2023
- Raw hash
- 9c1ca4d08ef51cdf0aa514c81abef12e74b66032b47051cfb114a1311991d7e3
Reporting entity
- Name
- Creedmoor Sports, Inc.norm: creedmoor sports
Victim entity
- Name
- CommerceV3norm: commercev3
- Domain
- commercev3.com
Incident
- Discovered
- May 3, 2023
- Materiality determined
- —
- Notification sent
- Jul 21, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Third party
- via CommerceV3, Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.