Creedmoor Sports, Inc.
ent_9ec7de0e6396f4cc350ab8a5
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
14,047
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Creedmoor Sports, Inc.
- Normalized
- creedmoor sports— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- New Hampshire State AGas victim2023-07-31
Creedmoor Sports notified NH AG of a data incident involving its third-party e-commerce provider, CommerceV3. Unauthorized access occurred Nov 2021–Dec 2022. Cardholder data and PII were potentially accessed. 87 NH residents affected. Notifications sent July 21, 2023.
- Massachusetts State AGas victim2023-07-28
Creedmoor Sports, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-28. 169 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2023-07-21
Creedmoor Sports, Inc. notified the WA AG of a data security incident involving its third-party e-commerce platform, CommerceV3. Unauthorized access occurred between Nov 24, 2021 and Dec 14, 2022. Creedmoor was notified on June 6, 2023. Cardholder data (names, emails, billing addresses, card numbers, CVVs) was potentially accessed. 518 WA residents affected. Notifications sent July 21, 2023, including credit monitoring.
- California State AGas victim2023-07-21
Creedmoor Sports, Inc. notified customers that an unauthorized party accessed CommerceV3, Inc.'s systems between Nov 24, 2021 and Dec 14, 2022. CommerceV3 informed Creedmoor on June 6, 2023, that cardholder data (name, email, billing address, payment card number, CVV, expiration date) was potentially accessed. Creedmoor offered 24 months of credit monitoring and fraud assistance.
- Maine State AGas victim2023-07-21
Creedmoor Sports, Inc., a point-of-sale vendor, reported an external system breach that occurred on December 14, 2022, and was discovered on June 6, 2023. The breach compromised the names and financial account or credit/debit card numbers (with security codes) of 14,047 individuals, including 53 Maine residents. Affected individuals were notified on July 21, 2023, and offered 12 months of credit monitoring and fraud assistance services.
- Indiana State AGas victim2023-07-21
Creedmoor Sports, Inc reported a data breach to the Indiana Attorney General. 294 Indiana residents were affected. 14,047 individuals affected in total.
- Oregon State AGas victim2023-07-21
Creedmoor Sports, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-21. The breach was discovered on 6/6/2023. 14,047 individuals were affected. Notice was sent on 7/21/2023.
- Vermont State AGas victim2023-07-21
Creedmoor Sports, Inc. notified consumers that its third-party e-commerce provider, CommerceV3, Inc., experienced a data security incident. An unauthorized party accessed CommerceV3's systems between November 24, 2021, and December 14, 2022. The breach potentially exposed customer names, email addresses, billing addresses, payment card numbers, CVV codes, and expiration dates. Creedmoor engaged forensic experts and is offering 12 months of free credit monitoring and fraud assistance to affected individuals.
- Montana State AGas reporting2023-07-21
Creedmoor Sports notified customers that CommerceV3, its e-commerce platform provider, experienced a data security incident. Unauthorized access occurred between Nov 24, 2021 and Dec 14, 2022. Cardholder data (name, email, billing address, card number, CVV, expiration) was potentially accessed. Creedmoor contacted CommerceV3 for security updates and offered 12 months of credit monitoring.
Supply-chain cascadesreviewed and confirmed
- Creedmoor Sports, Inc.’s filing is one of at least 31 in the CommerceV3 supply-chain incident (2023).