STC Holdings LLC
bd_e11fc2bc71477d0e · schema v1 · pii pii-v1
STC Holdings LLC (operating TobaccoPipes.com) notified customers of a data security incident involving the third-party BigCommerce application 'FreshClick.' A malicious actor skimmed credit card and personal information from shoppers between Oct 15 and Nov 7, 2024. The company uninstalled the app, secured systems, and engaged forensic investigators.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 15, 2024
Begins
Nov 8, 2024
Discovered
Nov 27, 2024
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Indiana State AGbd_f6e6a68a365e70d42024-11-27Verified
- Massachusetts State AGbd_11707656521ddf0f2024-11-28 · +1dVerified
- Maine State AGbd_f0cbd526669bc7082024-11-28 · +1dVerified
- Vermont State AGbd_5f342a4f10d596f12024-12-02 · +5dVerified
Show 1 more filing ↓Show fewer ↑up to 12d gap
- New Hampshire State AGbd_ff0dcc59156008642024-12-09 · +12dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Nov 27 (IN), last Dec 9 (NH) — a 12-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.