DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsTargetedFinancial accountIdentity (basic)LowContained

The Deck Store

bd_f656fa75a5ac90f1 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 28, 2020

Filed

Sep 4, 2020

To disclose

5 weeks

Affected

52state residents only

Linked

4 filings

Confidence

66%
Full breach record for The Deck Store

The Deck Store notified the NH Attorney General of a data incident affecting 52 NH residents. Malicious code on its e-commerce site captured payment card data (names, card numbers, CVVs) for transactions between March 16 and July 9, 2020. The company discovered the compromise on July 28, 2020, engaged forensic investigators, and began notifying affected customers on August 27, 2020.

Incident timeline

undetected · 134 days
discovery → filing · 5 weeks / 38 days

Mar 16, 2020

Begins

Jul 28, 2020

Discovered

Sep 4, 2020

Filed

vs. sector median

2 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Indiana State AGAug 27 · first
New Hampshire State AG+8d · this page

Pattern: first filing Aug 27 (IN), last Sep 4 (NH) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.