Blundstone (U.S.A.) Inc.
bd_d52977427ecd9344 · schema v1 · pii pii-v1
Full breach record for Blundstone (U.S.A.) Inc. →2 incidents on fileBlundstone U.S.A., Inc. disclosed a data breach affecting customer data from July 7 to August 14, 2024. An unauthorized third party exploited a vulnerability in the Adobe Commerce platform to install malicious code at the point of sale, collecting names, addresses, and payment card details including CVVs. Blundstone removed the code, patched the vulnerability, and engaged forensic counsel.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 7, 2024
Begins
Aug 15, 2024
Discovered
Sep 20, 2024
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Massachusetts State AGbd_40bb3d986f417e812024-09-20Verified
- California State AGbd_714ab241355383f22024-09-20Verified
- Maine State AGbd_7a9af778c88c72152024-09-20Verified
- Montana State AGbd_4d7eaaf90dd137d92024-09-14 · +6dCandidate
Show 2 more filings ↓Show fewer ↑up to 7d gap
- Indiana State AGbd_f45176f5ded33fe92024-09-14 · +6dVerified
- New Hampshire State AGbd_2676fe0caf8e95612024-09-13 · +7dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Sep 13 (NH), last Sep 20 (VT) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.