HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Nuna Baby Essentials, Inc.
bd_d4c0418644cd4190 · schema v1 · pii pii-v1
Full breach record for Nuna Baby Essentials, Inc. →Nuna Baby Essentials, Inc. disclosed that an unauthorized party may have accessed information entered on its website's checkout page between September 8, 2024, and December 6, 2024. The company identified suspicious activity on December 6, 2024. Affected data may include names, billing addresses, payment card numbers, expiration dates, and security codes. Nuna removed unauthorized code and enhanced website protections.
California clockDiscovered Dec 6, 2024 → Notified Feb 21, 202577d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_0b7b92e6170b3970Montana State AGfiled 2025-02-21Candidate
- bd_2dd65c8ad427d077Washington State AGfiled 2025-02-21Verified
- bd_7eee5014fe282a4dMaryland State AGfiled 2025-02-21Verified
- bd_863f7030737ba663New Hampshire State AGfiled 2025-02-21Verified
Show 4 more filings ↓Show fewer ↑
- bd_88ed36dc3d3a9accIndiana State AGfiled 2025-02-21Verified
- bd_b3eda8f7cf864f88Vermont State AGfiled 2025-02-21Verified
- bd_c3eebdb216aeccb8Oregon State AGfiled 2025-02-21Verified
- bd_efccb14d68a965e4Maine State AGfiled 2025-02-21Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-598989
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 21, 2025
- Raw hash
- ec0abe674963bf40641c31f3f6ad20440609b8ff72e9ac5be0912bfdb3ebdcb3
Reporting entity
- Name
- Nuna Baby Essentials, Inc.norm: nuna baby essentials
- Domain
- nunalife.com
Victim entity
- Name
- Nuna Baby Essentials, Inc.norm: nuna baby essentials
- Domain
- nunalife.com
Incident
- Discovered
- Dec 6, 2024
- Materiality determined
- —
- Notification sent
- Feb 21, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notifying regulatory authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- CA 60-day late · 77d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 6, 2024→ Notified: Feb 21, 202577d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.