Bombas
ent_91f6f3b477b6cb00f93d6940
Disclosures
15
State AG · 8 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
83,000
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Bombas
- Normalized
- bombas— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (15)newest first
- Massachusetts State AGas victim2020-06-04
Bombas LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-06-04. 3,108 Massachusetts residents were affected. The report records the breach type as paper.
- Montana State AGas victim2020-06-03
Bombas LLC notified Montana residents of a data breach involving malicious code on its e-commerce platform. The code, present from Nov 11, 2016 to Feb 16, 2017, potentially scraped customer names, addresses, and payment card data. Bombas added a security feature in Feb 2017 to stop the code and offered two years of free identity monitoring to affected individuals.
- New Hampshire State AGas victim2020-06-03
Bombas, LLC notified the NH AG of a security incident where malicious code on its Shopify e-commerce platform may have scraped customer data (names, addresses, payment card info) between Nov 11, 2016 and Feb 16, 2017. Approximately 680 NH residents affected. Bombas engaged Stroz Friedberg for investigation and offered 2 years of credit monitoring.
- Oregon State AGas victim2020-06-03
Bombas LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2020-06-03. The breach occurred during 11/11/2016 - 2/16/2017. 83,000 individuals were affected. Notice was sent on 6/3/2020.
- California State AGas victim2020-06-03
Bombas LLC discovered that malicious code designed to scrape payment card data and personal information may have been present on its e-commerce platform from November 11, 2016 to February 16, 2017. A security feature added in February 2017 stopped the code from functioning. An investigative report received May 20, 2020 could not rule out successful scraping of customer name, address, and payment card data. Customers were offered two years of identity monitoring services.
- Indiana State AGas victim2020-06-03
Bombas LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2016-11-11 and was reported on 2020-06-03. 1,728 Indiana residents were affected.
- Washington State AGas victim2020-06-03
Bombas LLC notified Washington AG of a security incident where malicious code on its Shopify e-commerce platform may have scraped customer PII and payment card data between Nov 11, 2016 and Feb 16, 2017. Discovered Dec 26, 2018 via Braintree report. 2,313 WA residents affected. Notifications mailed June 3, 2020.
- Illinois State AGas victim2020-01-01
BOMBAS LLC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-224). The register records the breach as discovered on December 26, 2018. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas victim2018-08-31
Bombas LLC notified customers of a historical data breach involving malicious code injection into its website between late 2014 and February 25, 2015. The incident potentially exposed names, addresses, and credit card information. Bombas identified the initial issue in early 2015 but re-examined the scope in 2018, leading to this supplemental notice for customers who made purchases between February 10 and February 25, 2015. The company has since migrated to a new e-commerce platform and implemented additional security measures. Free identity monitoring was offered to affected individuals.
- New Hampshire State AGas victim2018-08-31
Bombas, LLC filed a supplemental notice with the NH AG regarding a 2014-2015 Magento vulnerability. Malicious code injected into the e-commerce platform exposed customer names, addresses, and credit card info. Total affected: ~39,561 (252 NH residents). Bombas is offering 24 months of credit monitoring via Kroll and has migrated to a new platform.
- Massachusetts State AGas victim2018-05-21
Bombas reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-05-21. 1,361 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2018-05-18
Bombas, LLC notified customers of a data breach involving malware on its e-commerce platform. The malware existed from the site's launch on September 1, 2013, until removal on February 9, 2015. Approximately 41,000 customers who made credit card purchases during this period were affected. Data potentially included names, addresses, and credit card information. Bombas engaged Kroll to provide two years of free identity monitoring and migrated to a new platform.
- New Hampshire State AGas victim2018-05-18
Bombas, LLC notified the NH AG of a 2015 malware incident on its Magento e-commerce platform affecting ~41,000 customers (254 NH residents). Malware existed from Sept 2013 to Feb 2015. Bombas migrated to Shopify and offers 24 months of credit monitoring via Kroll.
- Oregon State AGas victim2018-05-18
Bombas, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2018-05-18. The breach occurred during 9/1/2013 - 1/15/2015, 1/27/2015 - 2/9/2015. The breach was discovered on 12/31/20141/27/2015. 41,000 individuals were affected. Notice was sent on 5/21/2018.
- California State AGas victim2018-05-18
Bombas, LLC disclosed a historical data breach affecting approximately 41,000 customers. Malware was identified in the code of a third-party e-commerce platform used for online sales between September 1, 2013, and February 9, 2015. The malware was initially removed on January 15, 2015. Affected data may include names, addresses, and credit card information. Bombas transitioned to a new e-commerce platform and offered two years of free identity monitoring through Kroll.