HackingStolen CredentialsData ExfiltratedPIIFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Outdoor Smart! Inc
bd_e9416fffa56fe7eb · schema v1 · pii pii-v1
Full breach record for Outdoor Smart! Inc →OutdoorSmart! Inc. notified consumers of a data breach affecting its Campfire Collective website. Unauthorized code capturing payment card information was present from Feb 15, 2024 to Nov 4, 2025. The company engaged third-party specialists, removed the code, and is offering 24 months of credit monitoring.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3168f9850d26a5b3Washington State AGfiled 2025-12-19Candidate
- bd_6c6eccc5335561c3Maine State AGfiled 2025-12-19Verified
- bd_c828eb1df170a599California State AGfiled 2025-12-19Verified
- bd_fe40f045ec9e37c2Indiana State AGfiled 2025-12-19Verified
Show 2 more filings ↓Show fewer ↑up to 19d gap
- bd_f53a3a1268dc51f0New Hampshire State AGfiled 2025-12-22(3d gap)Verified
- bd_8e546bbf2f313013Texas State AGfiled 2026-01-07(19d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-19-outdoor-smart-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2025
- Raw hash
- cd4b8336b1d4a36b729f21d7ee6bdf5a065137840c5ab010a45a728b3e93e354
Reporting entity
- Name
- Outdoor Smart! Incnorm: outdoor smart
Victim entity
- Name
- Outdoor Smart! Incnorm: outdoor smart
Incident
- Discovered
- Nov 3, 2025
- Materiality determined
- —
- Notification sent
- Dec 19, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.