North 40 Outfitters
ent_33cc1fb32734c13b00bdbd9f
Disclosures
14
State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
18,957
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- North 40 Outfitters
- Normalized
- north 40 outfitters— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- Montana State AGas victim2020-07-17
North 40 Outfitters notified customers that unauthorized access to its e-commerce site between Nov 27-30, 2019 may have compromised payment card info, names, addresses, and credentials. Discovered Feb 18, 2020. Forensic investigation confirmed scope. Transactions disabled, passwords reset, law enforcement notified.
- New Hampshire State AGas victim2019-04-29
Supplemental notice to NH AG regarding North 40 Outfitters data breach. Intruder introduced malicious script on webserver capturing card data (Dec 17, 2018 - Jan 22, 2019). 11 NH residents affected. Incident discovered Nov 8, 2018. Access blocked. PFI investigation concluded March 26, 2019.
- New Hampshire State AGas victim2019-02-19
North 40 Outfitters notified the NH AG that suspicious activity on its online payment platform between Feb 2 and Nov 20, 2018, may have exposed customer names, card numbers, CVVs, and usernames/passwords. Discovered Nov 8, 2018. 83 NH residents affected. Notices sent Feb 14, 2019. Forensic investigation engaged.
- Montana State AGas victim2019-02-14
North 40 Outfitters notified customers that credit/debit card data and credentials were compromised on its website. Unauthorized access occurred between Feb 2 and Nov 20, 2018. Suspicious activity was detected on Nov 8, 2018. Forensic investigation confirmed the breach. Affected data includes names, card numbers, CVVs, and usernames/passwords. The company engaged forensic investigators and notified regulators.
- Washington State AGas victim2019-02-14
North 40 Outfitters reported a cybersecurity incident where an intruder introduced a program on its webserver to capture customer credit/debit card data and credentials. The breach affected transactions from Feb 2, 2018, to Jan 22, 2019. 2,632 individuals were affected, including 315 Washington residents. Notices were sent in Feb 2019, with a supplemental notice in April 2019.
- Oregon State AGas victim2019-02-14
North 40 Outfitters reported a data breach to the Oregon Attorney General. The breach was reported on 2019-02-14. The breach occurred during 2/2/2018 - 11/20/2018. The breach was discovered on 11/8/20181/3/2019. 18,957 individuals were affected. Notice was sent on 2/14/2019.
- Massachusetts State AGas victim2019-02-14
North 40 Outfitters reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-02-14. 190 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2019-02-14
North 40 Outfitters disclosed that customer credit and debit card information, including names, card numbers, expiration dates, and CVVs, may have been subject to unauthorized access on its e-commerce website between February 2, 2018, and November 20, 2018. The incident was discovered on November 8, 2018, via suspicious activity monitoring. North 40 engaged a third-party forensic firm, contained the incident, and notified affected individuals and regulators in February 2019. No retail store transactions were affected.
- Washington State AGas victim2018-02-23
North 40 Outfitters reported unauthorized access to customer credit/debit card data and user credentials via its e-commerce site. The incident affected transactions between Jan 20, 2017 and Jan 29, 2018. North 40 was alerted on Jan 10, 2018. 2,671 Washington residents were notified on Feb 23, 2018. This is a supplemental notice.
- Oregon State AGas victim2018-02-23
North 40 Outfitters reported a data breach to the Oregon Attorney General. The breach was reported on 2018-02-23. The breach occurred during 1/20/2017 - 1/29/2018. The breach was discovered on 1/10/20181/29/2018. 14,734 individuals were affected. Notice was sent on 2/23/2018.
- New Hampshire State AGas victim2018-02-23
North 40 Outfitters notified the NH AG that customer credit/debit card info and account credentials were at risk of unauthorized access on its e-commerce site between Jan 20, 2017 and Jan 29, 2018. Discovered Jan 29, 2018. 44 NH residents notified. Incident reported to credit card companies; additional safeguards being implemented.
- California State AGas victim2018-02-23
North 40 Outfitters disclosed unauthorized access to customer credit and debit card data from its e-commerce website. The incident affected transactions between January 20, 2017, and January 29, 2018. Data exposed included names, card numbers, expiration dates, CVVs, and potentially account credentials. 864 California residents were notified on February 23, 2018. The company launched an investigation, reported to credit card companies, and implemented additional safeguards.
- Montana State AGas victim2018-02-23
North 40 Outfitters notified Montana residents of a data breach affecting e-commerce transactions between Jan 20, 2017 and Jan 29, 2018. Unauthorized access compromised names, credit/debit card numbers, expiration dates, CVVs, and potentially usernames/passwords. The company investigated, engaged law enforcement, and implemented additional security safeguards.
- Massachusetts State AGas victim2018-02-23
North 40 Outfitters reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-02-23. 116 Massachusetts residents were affected. The report records the breach type as electronic.