HackingVulnerability ExploitData ExfiltratedTargetedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Blundstone (U.S.A.) Inc.
bd_d52977427ecd9344 · schema v1 · pii pii-v1
Full breach record for Blundstone (U.S.A.) Inc. →Blundstone U.S.A., Inc. disclosed a data breach affecting customer data from July 7 to August 14, 2024. An unauthorized third party exploited a vulnerability in the Adobe Commerce platform to install malicious code at the point of sale, collecting names, addresses, and payment card details including CVVs. Blundstone removed the code, patched the vulnerability, and engaged forensic counsel.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_714ab241355383f2California State AGfiled 2024-09-20Verified
- bd_7a9af778c88c7215Maine State AGfiled 2024-09-20Verified
- bd_4d7eaaf90dd137d9Montana State AGfiled 2024-09-14(6d gap)Candidate
- bd_f45176f5ded33fe9Indiana State AGfiled 2024-09-14(6d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_2676fe0caf8e9561New Hampshire State AGfiled 2024-09-13(7d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-09-20-blundstone-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 20, 2024
- Raw hash
- 088b9e6cb39c8f5ab3d0f897956c50ee66d06106ce3e52efa6c27a2d88cb8595
Reporting entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
Victim entity
- Name
- Blundstone (U.S.A.) Inc.norm: blundstone usa
- Domain
- blundstone.com
Incident
- Discovered
- Aug 15, 2024
- Materiality determined
- —
- Notification sent
- Aug 16, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.