Springfield Armory
ent_a5b162c945c3b39c8590ab32
Disclosures
8
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
19,543
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Springfield Armory
- Normalized
- springfield armory— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- springfield-armory.com
Disclosure history (8)newest first
- Montana State AGas victim2021-08-16
Springfield Armory, Inc. notified Montana residents of a March 12, 2021 ransomware incident that encrypted files and resulted in the exfiltration of names and Social Security numbers. The company engaged a cybersecurity firm for investigation and offered one year of Experian Identity Works credit monitoring to affected individuals.
- Oregon State AGas victim2016-11-18
Springfield Armory reported a data breach to the Oregon Attorney General. The breach was reported on 2016-11-18. The breach occurred during 10/3/2015. The breach was discovered on 10/5/2016. 19,543 individuals were affected. Notice was sent on 11/18/2016.
- Washington State AGas victim2016-11-18
Springfield Armory notified the Washington AG of a cyberattack affecting 512 state residents. Unauthorized access to the web server occurred between Oct 3, 2015 and Oct 9, 2016, where code was installed to capture checkout data including payment card numbers and security codes. The incident was detected in late September 2016 after a payment card network reported unauthorized charges. The company engaged a cybersecurity firm, removed the malicious code, changed passwords, and implemented SQL security measures.
- California State AGas victim2016-11-18
Springfield Armory experienced a data breach affecting customers who made purchases on its website between October 3, 2015, and October 9, 2016. An unauthorized person gained access to the web server and installed code to copy checkout information, including names, addresses, payment card numbers, and security codes. The incident was discovered in late September 2015 after a payment card network reported unauthorized charges. The company engaged a cybersecurity firm, stopped the incident, and is strengthening website security.
- New Hampshire State AGas victim2016-11-18
Springfield Armory notified the NH Attorney General of a breach affecting 106 NH residents. Unauthorized access to the web server occurred between Oct 3, 2015 and Oct 9, 2016. Attackers installed code to copy checkout data (names, addresses, payment card numbers, CVVs) via SQL injection. Incident contained; security measures updated.
- Massachusetts State AGas victim2016-11-18
Springfield Armory reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-11-18. 73 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2016-11-18
Springfield Armory notified customers of a payment card skimming incident. Unauthorized access to the web server occurred between Oct 3, 2015 and Oct 9, 2016. Attackers installed code to copy checkout data including names, addresses, and full payment card details. The incident was contained and a security firm was engaged.
- Montana State AGas victim2016-11-18
Springfield Armory notified Montana residents of a payment card skimming incident. Unauthorized access occurred between Oct 3, 2015 and Oct 9, 2016. Attackers installed code on the web server to copy checkout data including names, addresses, and full payment card details. The incident was contained and a security firm was engaged.