DisclosureLens
HackingRetail & ConsumerTechnologyRetailSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

Creedmoor Sports, Inc.

bd_d4b9b5ed6965643e · schema v1 · pii pii-v1

Severity

Low

Discovered

May 3, 2023

Filed

Jul 21, 2023

To disclose

11 weeks

Affected

Not disclosed

Confidence

66%
Full breach record for Creedmoor Sports, Inc.3 incidents on file

Creedmoor Sports, Inc. notified consumers that its third-party e-commerce provider, CommerceV3, Inc., experienced a data security incident. An unauthorized party accessed CommerceV3's systems between November 24, 2021, and December 14, 2022. The breach potentially exposed customer names, email addresses, billing addresses, payment card numbers, CVV codes, and expiration dates. Creedmoor engaged forensic experts and is offering 12 months of free credit monitoring and fraud assistance to affected individuals.

Vermont clock VT AG >45 bday11 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 525 days
discovery → filing · 11 weeks / 79 days

Nov 24, 2021

Begins

May 3, 2023

Discovered

Jul 21, 2023

Filed

vs. sector median

+4 wks slower

Part of CommerceV3 supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.