HackingRetail & ConsumerRetailCapture App DataPacket SnifferData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIPCILowContained
Betterdoor.com
bd_f6e2d5faac76063b · schema v1 · pii pii-v1
Full breach record for Betterdoor.com →Betterdoor.com, an e-commerce retailer, discovered on November 22, 2024 that unauthorized code had been injected into its website checkout process at some point after July 30, 2023. The malicious code had the capability to capture payment card information and names entered during checkout. 44 Maine residents were among the 9,218 total individuals potentially affected. No identity theft protection services were offered. Notification letters were mailed December 31, 2024.
Maine clockDiscovered Nov 22, 2024 → Filed with AG Dec 31, 202439d ⏱ ME AG >30d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1fe26712649dd5bdNew Hampshire State AGfiled 2024-12-31Verified
- bd_27adaef32e300983Vermont State AGfiled 2024-12-31Verified
- bd_ae400b6021c091deMontana State AGfiled 2024-12-31Verified
- bd_cc8d151de9eddae7Indiana State AGfiled 2024-12-31Verified
Show 1 more filing ↓Show fewer ↑
- bd_ff8fd619bd94a909California State AGfiled 2024-12-31Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/f71c1d0a-6fd9-48a5-a352-728db5492644.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 31, 2024
- Raw hash
- ffa4cd5ffa814bca3d40c801594fe268ec4b433fdd0e3fc0bb5af94e8df0b2a8
Reporting entity
- Name
- Betterdoor.comnorm: betterdoorcom
- Domain
- betterdoor.com
Victim entity
- Name
- Betterdoor.comnorm: betterdoorcom
- Domain
- betterdoor.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Nov 22, 2024
- Materiality determined
- —
- Notification sent
- Dec 31, 2024
- Affected individuals
- 44
- Data types
- PIIPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1059 Command and Scripting InterpreterT1056.003 Web Portal CaptureT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(39 days from discovery to filing)
- Compliance flags
- ME AG >30d · 39d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Nov 22, 2024→ Filed with AG: Dec 31, 202439d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.