HackingSkimmerCustomer Data InvolvedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Special Buys Clothing Inc.
bd_e92b589788940062 · schema v1 · pii pii-v1
Full breach record for Special Buys Clothing Inc. →Special Buys Clothing Inc. (DBA Bargain Balloons) experienced a data breach between September 27 and November 7, 2022. An unauthorized outsider inserted malicious skimming code on the website's checkout page, capturing customer names, addresses, emails, phone numbers, and credit card information. The incident was discovered in October 2022 after a customer reported fraud. The company secured the website, removed the code, and offered 12 months of credit monitoring.
California clockDiscovered Oct 1, 2022 → Notified Dec 15, 202275d ✗ CA 60-day late16 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_47ae83101c7c238cMaine State AGfiled 2023-01-20(1d gap)Verified
- bd_b7879b167a37cbd0New Hampshire State AGfiled 2023-01-30(11d gap)Verified
- bd_7f2e9177a73a8535Montana State AGfiled 2022-12-13(37d gap)Verified
- bd_d002a3fd6a695621New Hampshire State AGfiled 2022-12-12(38d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 41d gap
- bd_92d668249e35cf79Maine State AGfiled 2022-12-09(41d gap)Candidate
- bd_d39d671c575ae478California State AGfiled 2022-12-09(41d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-561985
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 19, 2023
- Raw hash
- 1ce112ef9430d07605d853313691be4e2747db29f0486acd52a6c7b7cebab333
Reporting entity
- Name
- Special Buys Clothing Inc.norm: special buys clothing
- Domain
- bargainballoons.com
Victim entity
- Name
- Special Buys Clothing Inc.norm: special buys clothing
- Domain
- bargainballoons.com
Incident
- Discovered
- Oct 1, 2022
- Materiality determined
- —
- Notification sent
- Dec 15, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical MediumT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified applicable privacy commissioners
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(110 days from discovery to filing)
- Compliance flags
- CA 60-day late · 75d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 1, 2022→ Notified: Dec 15, 202275d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.