Bombas
bd_f50804e00f830456 · schema v1 · pii pii-v1
Full breach record for Bombas →4 incidents on fileBombas LLC notified Washington AG of a security incident where malicious code on its Shopify e-commerce platform may have scraped customer PII and payment card data between Nov 11, 2016 and Feb 16, 2017. Discovered Dec 26, 2018 via Braintree report. 2,313 WA residents affected. Notifications mailed June 3, 2020.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 11, 2016
Begins
Dec 26, 2018
Discovered
Jun 3, 2020
Filed
vs. sector median
+68 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Montana State AGbd_032c860efe4a2ff32020-06-03Candidate
- New Hampshire State AGbd_2e0f55b86f1170a32020-06-03Verified
- Oregon State AGbd_2f92b42d2848b3ab2020-06-03Verified
- California State AGbd_9101cc153fd11ef12020-06-03Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- Indiana State AGbd_9b29684e29b93fe12020-06-03Verified
- Massachusetts State AGbd_43c63091f0426d8f2020-06-04 · +1dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.