Blundstone (U.S.A.) Inc.
ent_e3f9650f4fdacf98
Disclosures
11
State AG · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
6,156
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Blundstone (U.S.A.) Inc.
- Normalized
- blundstone usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- blundstone.com
Disclosure history (11)newest first
- Massachusetts State AGas victim2024-12-06
Blundstone (U.S.A.) Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-12-06. 2 Massachusetts residents were affected.
- Montana State AGas victim2024-12-04
Blundstone (U.S.A.) Inc. notified customers of a data breach on November 12, 2024, where an unauthorized party exploited a malicious plug-in on its Adobe Commerce e-commerce platform. The attacker installed code to duplicate the checkout page and capture personal and payment card information (including CVV) for a 2.5-hour window. Blundstone removed the code, patched the vulnerability, and engaged forensic counsel.
- Vermont State AGas victim2024-11-28
Blundstone (U.S.A.) Inc. disclosed that an unauthorized third party exploited a plug-in on its Adobe Commerce e-commerce platform on November 12, 2024, to install malicious code that duplicated the checkout page. This allowed the collection of contact and payment information (including CVV) for approximately two and a half hours. The company secured systems, removed malicious code, and applied patches.
- Indiana State AGas victim2024-11-28
Blundstone (USA) Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-11-12 and was reported on 2024-11-28. 1 Indiana residents were affected. 51 individuals affected in total.
- Massachusetts State AGas victim2024-09-20
Blundstone (U.S.A.) Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-09-20. 205 Massachusetts residents were affected.
- California State AGas victim2024-09-20
Blundstone (U.S.A.) Inc. experienced a security incident where an unauthorized third party exploited a vulnerability in the Adobe Commerce platform to install malicious code on the e-commerce checkout page. This allowed the collection of contact and payment information from July 7, 2024, to August 14, 2024. The incident was discovered on August 15, 2024. Affected data includes names, addresses, phone numbers, and payment card details (including CVV). Blundstone removed the malicious code, applied patches, and engaged a cybersecurity firm.
- Maine State AGas victim2024-09-20
Blundstone (U.S.A.) Inc. reported a data breach affecting 6,156 individuals, including 77 Maine residents. Unauthorized access occurred between July 7, 2024, and August 14, 2024, via exploitation of a vulnerability in the Adobe Commerce platform. The attacker installed malicious code to capture customer names, addresses, phone numbers, and payment card information (including CVV). Blundstone removed the code, patched the vulnerability, and engaged forensic counsel. Notices were sent on September 14, 2024.
- Vermont State AGas victim2024-09-20
Blundstone U.S.A., Inc. disclosed a data breach affecting customer data from July 7 to August 14, 2024. An unauthorized third party exploited a vulnerability in the Adobe Commerce platform to install malicious code at the point of sale, collecting names, addresses, and payment card details including CVVs. Blundstone removed the code, patched the vulnerability, and engaged forensic counsel.
- Montana State AGas victim2024-09-14
Blundstone (U.S.A.) Inc. notified Montana residents of a data breach involving its Adobe Commerce e-commerce platform. An unauthorized third party exploited a vulnerability to install malicious code that duplicated the checkout page and captured customer PII and payment card data (including CVV) between July 7 and August 14, 2024. Blundstone discovered the incident on August 15, 2024, removed the malware, patched the vulnerability, and engaged forensic counsel.
- Indiana State AGas victim2024-09-14
Blundstone (USA) Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-07 and was reported on 2024-09-14. 56 Indiana residents were affected. 6,156 individuals affected in total.
- New Hampshire State AGas victim2024-09-13
Blundstone (U.S.A.) Inc. notified the NH AG of a security incident affecting 44 NH residents. An unauthorized third party exploited a vulnerability in the Adobe Commerce platform between July 7 and August 14, 2024, to install malicious code that duplicated the checkout page and collected contact and payment information. Blundstone discovered the incident on August 15, 2024, engaged forensic investigators and legal counsel, removed the malicious code, and applied security patches.