Blade HQ
ent_1051c67eee17908202656037
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
90,000
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Blade HQ
- Normalized
- blade hq— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bladehq.com
Disclosure history (9)newest first
- Massachusetts State AGas victim2021-04-24
Blade HQ reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-04-24. 1,863 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2021-04-21
Blade HQ reported a data breach to the Indiana Attorney General. The breach occurred on 2021-01-07 and was reported on 2021-04-21. 2,158 Indiana residents were affected. 90,000 individuals affected in total.
- Montana State AGas victim2021-04-20
Blade HQ, LLC notified customers of a data breach where an unauthorized intruder uploaded malware to its websites (bladehq.com, etc.) between Jan 7 and Apr 11, 2021. The malware skimmed customer transaction data including names, addresses, and credit card details. Blade HQ engaged forensic investigators, removed the malware, deployed new servers, and implemented additional security measures.
- Maine State AGas victim2021-04-20
Blade HQ, a commercial entity based in Pleasant Grove, UT, reported an external system breach (hacking) occurring between January 7, 2021, and April 11, 2021. The breach was discovered on March 22, 2021, and affected approximately 90,000 individuals, including 557 Maine residents. Compromised data included names and financial account or credit/debit card numbers (with security codes/PINs). Written notification was sent on April 30, 2021. No identity theft protection services were offered.
- Oregon State AGas victim2021-04-19
Blade HQ reported a data breach to the Oregon Attorney General. The breach was reported on 2021-04-19. The breach occurred during 1/7/2021 - 4/11/2021. The breach was discovered on 3/22/2021. 90,000 individuals were affected. Notice was sent on 4/19/2021.
- South Carolina State AGas victim2021-04-19
Blade HQ, LLC notified customers of a data breach where unauthorized parties gained access to hosted servers via compromised admin credentials. Malicious JavaScript was uploaded to skim customer transaction data (names, addresses, credit card numbers, CVVs) between Jan 7 and Apr 11, 2021. The incident was detected on March 18, 2021. Blade HQ engaged forensic investigators, removed malware, deployed new servers, and implemented additional security measures.
- California State AGas victim2021-04-19
Blade HQ experienced a data breach involving malware uploaded to its e-commerce websites (bladehq.com, etc.) between January 7, 2021, and March 22, 2021. The malware was used to 'skim' customer transaction data, potentially exposing names, addresses, email addresses, credit/debit card numbers, expiration dates, and CVV codes. The company became aware of unusual activity in late March 2021, engaged forensic investigators, removed the malware, deployed new servers, and implemented additional security measures. No specific count of affected individuals was disclosed.
- Washington State AGas victim2021-04-19
Blade HQ, LLC, an online retailer, disclosed a cybersecurity incident where unauthorized parties gained access to its hosted server infrastructure, likely via a compromised admin account. The attackers uploaded malicious JavaScript to perform credit card skimming on customer transactions. The intrusion occurred from January 7, 2021, to March 22, 2021, and briefly on April 11, 2021. Blade HQ discovered the unusual activity on March 18, 2021, engaged forensic investigators, and began notifying affected customers in late April 2021. Approximately 3,090 Washington residents were potentially affected, with data including names, addresses, and credit card details compromised.
- New Hampshire State AGas victim2021-04-19
Blade HQ, LLC, an online retailer of outdoor equipment, disclosed a security incident in New Hampshire affecting 651 state residents. Unauthorized parties gained access to the company's hosted server infrastructure, likely via a compromised admin account, and uploaded malicious JavaScript code to perform credit card transaction skimming. The malicious code existed from approximately January 7, 2021, to March 22, 2021, and briefly on April 11, 2021. Affected data included customer names, addresses, email addresses, credit card numbers, expiration dates, and CVV codes. The company engaged a forensic firm, patched vulnerabilities, migrated to a secure server, and implemented new security measures. Notifications to affected customers began on April 20, 2021.