HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
North 40 Outfitters
bd_e64ead328d32d972 · schema v1 · pii pii-v1
Full breach record for North 40 Outfitters →North 40 Outfitters reported unauthorized access to its e-commerce payment platform between Feb 2 and Nov 20, 2018. Suspicious activity was detected on Nov 8, 2018. Customer names, credit/debit card numbers, CVVs, and potentially usernames/passwords were compromised. Notice was sent to affected individuals on Feb 14, 2019. Forensic investigation was engaged.
California clockDiscovered Nov 8, 2018 → Notified Feb 14, 201998d ✗ CA 60-day late14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_4b668a3582761b70Montana State AGfiled 2019-02-14Candidate
- bd_91ec3d5509abff2eWashington State AGfiled 2019-02-14Verified by operator
- bd_9f6005ba31246951Oregon State AGfiled 2019-02-14Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144716
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2019
- Raw hash
- f2eb266ec83fbeec149c1111c1838f0c3335abe7c3e28f49cd7e11fe81a2656d
Reporting entity
- Name
- North 40 Outfittersnorm: north 40 outfitters
Victim entity
- Name
- North 40 Outfittersnorm: north 40 outfitters
Incident
- Discovered
- Nov 8, 2018
- Materiality determined
- —
- Notification sent
- Feb 14, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this incident to the credit card companiesproviding written notice of this incident to other state regulators and the consumer reporting agencies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- CA 60-day late · 98d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 8, 2018→ Notified: Feb 14, 201998d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.