BSN Sports, Inc.
ent_019e22f9f2a0051561508c1b25438460
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
23,834
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BSN Sports, Inc.
- Normalized
- bsn sports— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493007YNNGXNB46B736
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- New Hampshire State AGas victim2021-03-02
BSN Sports, LLC notified the New Hampshire Attorney General of a data breach affecting 136 NH residents. A criminal actor injected malicious code onto four eCommerce checkout pages between April 24, 2019, and January 5, 2021. The code scraped payment card account numbers, expiration dates, and CVV2 numbers, along with customer names. BSN removed the code, notified its payment processor, and began notifying consumers on February 26, 2021, offering one year of Dark Web Monitoring.
- Massachusetts State AGas victim2021-02-26
BSN Sports, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-02-26. 475 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2021-02-26
BSN Sports, LLC reported an external system breach that occurred between April 24, 2019, and January 5, 2021. The breach was discovered on February 2, 2021. The compromised information includes names or other personal identifiers in combination with financial account numbers or credit/debit card numbers and their associated security codes or PINs. A total of 72 Maine residents were affected out of 23,834 individuals in total. BSN Sports began notifying affected consumers on February 26, 2021, and offered one year of Epiq's Dark Web Monitoring services.
- Washington State AGas victim2021-02-26
BSN Sports, LLC notified Washington AG that a criminal actor injected malicious code onto four eCommerce checkout pages, scraping payment card data (account number, expiration, CVV2) and customer names. The incident occurred between April 24, 2019, and January 5, 2021. BSN discovered the compromise on February 2, 2021, removed the code, and began notifying 523 affected Washington residents on February 26, 2021, offering one year of dark web monitoring.
- Montana State AGas victim2021-02-26
BSN Sports, LLC notified customers that a criminal actor compromised the security of checkout pages on four eCommerce websites between April 24, 2019, and January 5, 2021. The actor copied payment card data (account number, expiration, verification number) along with names, addresses, and contact information. BSN secured the sites, engaged forensic/root-cause analysis, and offered one year of dark web monitoring.
- California State AGas victim2021-02-26
BSN Sports, LLC disclosed that a criminal actor compromised the security of checkout pages on four eCommerce websites between April 24, 2019, and January 5, 2021. The attacker copied payment card account numbers, expiration dates, verification numbers, names, addresses, and contact information. BSN secured the websites, implemented technical safeguards, and offered one year of dark web monitoring to affected customers.
- Oregon State AGas victim2021-02-26
BSN Sports, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2021-02-26. 23,834 individuals were affected.
- Indiana State AGas victim2021-02-26
BSN Sports, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2019-04-24 and was reported on 2021-02-26. 511 Indiana residents were affected. 23,834 individuals affected in total.
- Illinois State AGas victim2021-01-01
BSN SPORTS, LLC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-098). The register records the breach as discovered on January 2, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.