Merchant One, Inc.
bd_e39d2ca718b31566 · schema v1 · pii pii-v1
Full breach record for Merchant One, Inc. →Merchant One, Inc. notified the California Attorney General of an incident where an unknown individual may have accessed specific files in its system via a third-party IT provider. The company became aware of suspicious activity on February 24, 2020. The potentially impacted data included personal information such as names and addresses. Merchant One engaged forensic specialists, confirmed system security, implemented enhanced email security, multi-factor authentication, and additional training, and transitioned to a different IT provider. Identity monitoring services were offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 24, 2020
Begins
Feb 24, 2020
Discovered
Nov 23, 2020
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_0cd6828729bbce812020-11-23Verified
- Massachusetts State AGbd_1410d50c584653da2020-11-23Verified
- Maine State AGbd_6b85e9a03898bdae2020-11-23Candidate
- New Hampshire State AGbd_feb24aac42208b292020-11-30 · +7dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Nov 23 (IN), last Nov 30 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.