Blundstone (U.S.A.) Inc.
ent_e3f9650f4fdacf98
Disclosures
9
State AG · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
6,156
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Blundstone (U.S.A.) Inc.
- Normalized
- blundstone usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- blundstone.com
Disclosure history (9)newest first
- 🦬Montana State AGas victim2024-12-04
Blundstone U.S.A. Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2024-12-04. The breach occurred on 11/12/2024. 1 Montana residents were affected.
- 🍁Vermont State AGas victim2024-11-28
Blundstone (U.S.A.) Inc. disclosed a data breach affecting customers who made online purchases. An unauthorized third party exploited a vulnerability in a plug-in on the Adobe Commerce (Magento) platform on November 12, 2024, to install malicious code that duplicated the checkout page. The attacker collected personal and payment information, including names, addresses, phone numbers, and payment card details with CVVs, for a period of 2.5 hours. Blundstone removed the malicious code, applied security patches, and engaged outside cybersecurity and legal counsel.
- 🏎️Indiana State AGas victim2024-11-28
Blundstone (USA) Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-11-12 and was reported on 2024-11-28. 1 Indiana residents were affected. 51 individuals affected in total.
- 🐻California State AGas victim2024-09-20
Blundstone (U.S.A.) Inc. experienced a security incident where an unauthorized third party exploited a vulnerability in the Adobe Commerce platform to install malicious code on the e-commerce checkout page. This allowed the collection of contact and payment information from July 7, 2024, to August 14, 2024. The incident was discovered on August 15, 2024. Affected data includes names, addresses, phone numbers, and payment card details (including CVV). Blundstone removed the malicious code, applied patches, and engaged a cybersecurity firm.
- 🦞Maine State AGas victim2024-09-20
Blundstone (U.S.A.) Inc. disclosed a web skimming incident affecting its Adobe Commerce (Magento) e-commerce platform. An unauthorized third party exploited a vulnerability in the platform between July 7, 2024 and August 14, 2024, installing malicious code that duplicated the checkout webpage to capture customer contact and payment card information at point of sale. Discovered August 15, 2024; 77 Maine residents and 6,156 total individuals were affected.
- 🍁Vermont State AGas victim2024-09-20
Blundstone U.S.A., Inc. disclosed a data breach affecting customer data from July 7 to August 14, 2024. An unauthorized third party exploited a vulnerability in the Adobe Commerce platform to install malicious code at the point of sale, collecting names, addresses, and payment card details including CVVs. Blundstone removed the code, patched the vulnerability, and engaged forensic counsel.
- 🦬Montana State AGas victim2024-09-14
Blundstone (U.S.A.) Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2024-09-14. The breach occurred from 7/7/2024 to 8/14/2024. 49 Montana residents were affected.
- 🏎️Indiana State AGas victim2024-09-14
Blundstone (USA) Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-07 and was reported on 2024-09-14. 56 Indiana residents were affected. 6,156 individuals affected in total.
- ⛰️New Hampshire State AGas victim2024-09-13
Blundstone (U.S.A.) Inc. notified the NH AG of a security incident affecting 44 NH residents. An unauthorized third party exploited a vulnerability in the Adobe Commerce platform between July 7 and August 14, 2024, to install malicious code that duplicated the checkout page and collected contact and payment information. Blundstone discovered the incident on August 15, 2024, engaged forensic investigators and legal counsel, removed the malicious code, and applied security patches.