STEIN MART, INC.
bd_fb11207da2b13acd · schema v1 · pii pii-v1
Full breach record for STEIN MART, INC. →3 incidents on fileStein Mart, Inc. notified the NH AG of a third-party vendor breach involving Annex Cloud. Unauthorized code inserted into Annex Cloud's login app could have captured customer PII and payment card data (including CVV) between Dec 28, 2017 and July 9, 2018. Stein Mart removed the app and notified 195 NH residents starting Nov 13, 2018.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 28, 2017
Begins
Aug 6, 2018
Discovered
Nov 14, 2018
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_7be7408ca16516132018-11-13 · +1dCandidate
- California State AGbd_8a74ba926b9e0e7f2018-11-13 · +1dVerified
- Washington State AGbd_dcd4b744c73963962018-11-13 · +1dVerified by operator
- Oregon State AGbd_f55c7eaa8530a3af2018-11-13 · +1dVerified by operator
Show 1 more filing ↓Show fewer ↑up to 13d gap
- California State AGbd_f29c876cc79bf6702018-11-27 · +13dCandidate
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Nov 13 (MT), last Nov 27 (CA) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.