STEIN MART, INC.
bd_dcd4b744c7396396 · schema v1 · pii pii-v1
Full breach record for STEIN MART, INC. →3 incidents on fileStein Mart, Inc. notified the Washington AG of a third-party vendor breach involving Annex Cloud. Unauthorized code inserted into Annex Cloud's social login application could have captured customer checkout data (name, address, email, payment card info, CVV) between Dec 28, 2017 and Jul 9, 2018. Stein Mart removed the app and notified 680 Washington residents starting Nov 13, 2018.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 28, 2017
Begins
Aug 6, 2018
Discovered
Nov 13, 2018
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_7be7408ca16516132018-11-13Candidate
- California State AGbd_8a74ba926b9e0e7f2018-11-13Verified
- Oregon State AGbd_f55c7eaa8530a3af2018-11-13Verified by operator
- New Hampshire State AGbd_fb11207da2b13acd2018-11-14 · +1dVerified
Show 1 more filing ↓Show fewer ↑up to 14d gap
- California State AGbd_f29c876cc79bf6702018-11-27 · +14dCandidate
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Nov 13 (MT), last Nov 27 (CA) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.