DisclosureLens
MalwareRetail & ConsumerRetailInfostealerData ExfiltratedCustomer Data InvolvedFinancial accountIdentity (basic)LowContained

Slate & Tell

bd_fa4b8c6820643a29 · schema v1 · pii pii-v1

Severity

Low

Discovered

Nov 24, 2020

Filed

Apr 2, 2021

To disclose

18 weeks

Affected

624state residents only

Linked

7 filings

Confidence

69%
Full breach record for Slate & Tell

Slate & Tell, LLC notified Washington AG of a cyberattack involving malware stealing payment card data (names, addresses, card numbers, CVVs) from its e-commerce site. The incident occurred between March 1, 2020, and January 15, 2021. Suspicious activity was first detected on November 24, 2020. 624 Washington residents were affected. Notices were sent on April 2, 2021.

Washington clock WA AG >30d18 weeks discovery → filing

Incident timeline

undetected · 268 days
discovery → filing · 18 weeks / 129 days

Mar 1, 2020

Begins

Nov 24, 2020

Discovered

Apr 2, 2021

Filed

vs. sector median

+11 wks slower

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filings

Filing propagation · 7 filings · 7 states

View merged incident ↗
Indiana State AGApr 2 · first
Oregon State AGApr 2 · first
California State AGApr 2 · first
Montana State AGApr 2 · first
Maine State AGApr 2 · first
Washington State AGApr 2 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.