Bombas, LLC
ent_91f6f3b477b6cb00f93d6940
Disclosures
8
State AG · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
83,000
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Bombas, LLC
- Normalized
- bombas— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- 🦬Montana State AGas victim2020-06-03
Bombas LLC reported a data breach to the Montana Attorney General. The breach was reported on 2020-06-03. The breach occurred from 11/11/2016 to 2/16/2017. 289 Montana residents were affected.
- 🦫Oregon State AGas victim2020-06-03
Bombas LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2020-06-03. The breach occurred during 11/11/2016 - 2/16/2017. 83,000 individuals were affected. Notice was sent on 6/3/2020.
- 🐻California State AGas victim2020-06-03
Bombas LLC discovered that malicious code designed to scrape payment card data and personal information may have been present on its e-commerce platform from November 11, 2016 to February 16, 2017. A security feature added in February 2017 stopped the code from functioning. An investigative report received May 20, 2020 could not rule out successful scraping of customer name, address, and payment card data. Customers were offered two years of identity monitoring services.
- 🌲Washington State AGas victim2020-06-03
Bombas LLC, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2018-12-26 and filed notice on 2020-06-03. 2,313 Washington residents were affected. 525 days elapsed between awareness and notification. 775 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2018-08-31
Bombas LLC reported a historical data breach involving malicious code injected into its e-commerce website between September 2014 and February 2015. The incident potentially exposed customer names, addresses, and credit card information for purchases made between February 10 and February 25, 2015. Bombas engaged Kroll to provide two years of free identity monitoring and migrated to a new e-commerce platform.
- 🦬Montana State AGas victim2018-05-18
Bombas, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2018-05-18. The breach occurred from 1/15/2015 to 2/9/2015. 90 Montana residents were affected.
- 🦫Oregon State AGas victim2018-05-18
Bombas, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2018-05-18. The breach occurred during 9/1/2013 - 1/15/2015, 1/27/2015 - 2/9/2015. The breach was discovered on 12/31/20141/27/2015. 41,000 individuals were affected. Notice was sent on 5/21/2018.
- 🐻California State AGas victim2018-05-18
Bombas, LLC reported a data breach involving malware embedded in its third-party e-commerce platform. The malware existed from September 1, 2013, until February 9, 2015, potentially affecting approximately 41,000 customers who made credit card purchases. The incident exposed names, addresses, and credit card information. Bombas engaged Kroll to provide two years of free identity monitoring and transitioned to a new e-commerce platform.