North 40 Outfitters
bd_e64ead328d32d972 · schema v1 · pii pii-v1
Full breach record for North 40 Outfitters →3 incidents on fileNorth 40 Outfitters disclosed that customer credit and debit card information, including names, card numbers, expiration dates, and CVVs, may have been subject to unauthorized access on its e-commerce website between February 2, 2018, and November 20, 2018. The incident was discovered on November 8, 2018, via suspicious activity monitoring. North 40 engaged a third-party forensic firm, contained the incident, and notified affected individuals and regulators in February 2019. No retail store transactions were affected.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 2, 2018
Begins
Nov 8, 2018
Discovered
Feb 14, 2019
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Montana State AGbd_4b668a3582761b702019-02-14Candidate
- Washington State AGbd_91ec3d5509abff2e2019-02-14Verified by operator
- Oregon State AGbd_9f6005ba312469512019-02-14Verified
- Massachusetts State AGbd_b52d773a93fb37ee2019-02-14Verified
Show 2 more filings ↓Show fewer ↑up to 74d gap
- New Hampshire State AGbd_c382d77b4fab019c2019-02-19 · +5dVerified
- New Hampshire State AGbd_413daf193a69e1642019-04-29 · +74dVerified
Filing propagation · 7 filings · 6 states
View merged incident ↗Pattern: first filing Feb 14 (MT), last Apr 29 (NH) — a 74-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.