DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountFinancial credentialsHighContained

Pentel of America, Ltd.

bd_f6d59a7e13766dd7 · schema v1 · pii pii-v1

Severity

High

Discovered

Jan 20, 2009

Filed

Mar 3, 2009

To disclose

6 weeks

Affected · nationwide

2,0767 in this filing

Confidence

65%

Pentel of America, Ltd. reported a cybersecurity incident involving its online retail outlet (www.pentelstore.com). Unidentified actors gained unauthorized access between December 11, 2008, and January 20, 2009, accessing personal data of online shoppers, including names, billing addresses, email addresses, phone numbers, credit card numbers, expiration dates, and CV2 codes. An estimated 2,076 individuals were affected, including 7 New Hampshire residents. Pentel notified the New Hampshire Attorney General, engaged law enforcement (Grapevine PD and U.S. Secret Service), retained Kroll Inc. for credit monitoring services, and mailed notification letters to affected individuals starting February 19, 2009.

Incident timeline

undetected · 40 days
discovery → filing · 6 weeks / 42 days

Dec 11, 2008

Begins

Jan 20, 2009

Discovered

Mar 3, 2009

Filed

vs. sector median

1 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,076 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.