Merchant One, Inc.
bd_e39d2ca718b31566 · schema v1 · pii pii-v1
Full breach record for Merchant One, Inc. →Merchant One, Inc. notified the California Attorney General of an incident where an unknown individual may have accessed specific files in its system via a third-party IT provider. The company became aware of suspicious activity on February 24, 2020. The potentially impacted data included personal information such as names and addresses. Merchant One engaged forensic specialists, confirmed system security, implemented enhanced email security, multi-factor authentication, and additional training, and transitioned to a different IT provider. Identity monitoring services were offered to affected individuals.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-196442
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 23, 2020
- Raw hash
- 7b046085883ee078fd9156ead626ea2df74363e3371040333018eaae6cb6cee6
Reporting entity
- Name
- Merchant One, Inc.norm: merchant one
Victim entity
- Name
- Merchant One, Inc.norm: merchant one
Incident
- Discovered
- Feb 24, 2020
- Materiality determined
- —
- Notification sent
- Oct 26, 2020
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Third party
- via third-party IT provider
- Initial access
- supply_chain
Compliance
- Time to disclose
- 39 weeks(273 days from discovery to filing)
- Compliance flags
- CA 60-day late · 245d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 24, 2020→ Notified: Oct 26, 2020245d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.