HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Guidecraft, Inc
bd_f58c952c55705a1d · schema v1 · pii pii-v1
Full breach record for Guidecraft, Inc →Guidecraft, Inc. notified consumers of a data breach involving unauthorized code injection on its e-commerce website (guidecraft.com). The incident, discovered on December 29, 2022, potentially exposed customer names, billing/shipping addresses, and credit/debit card numbers for transactions made between September 2021 and February 2023. Guidecraft engaged forensic specialists and secured the site. 36 Rhode Island residents were explicitly identified as impacted.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_4e513b290187f702Maine State AGfiled 2023-03-23(28d gap)Verified
- bd_6bf63214db4c2b3aCalifornia State AGfiled 2023-03-23(28d gap)Candidate
- bd_782746619e5e1e0bMontana State AGfiled 2023-03-23(28d gap)Verified
- bd_78b2bed0ea9d45ebNew Hampshire State AGfiled 2023-03-27(32d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-02-23-guidecraft-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2023
- Raw hash
- 37e8bf08bf3072ba0fa38e6a7859f1f2ed7aef886660e027b3320930c187c162
Reporting entity
- Name
- Guidecraft, Incnorm: guidecraft
- Domain
- guidecraft.com
Victim entity
- Name
- Guidecraft, Incnorm: guidecraft
- Domain
- guidecraft.com
Incident
- Discovered
- Dec 29, 2022
- Materiality determined
- —
- Notification sent
- Mar 23, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1074 Data Staged
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.