Confirmed breach. Intrusion Jan 3, 2019–Jan 24, 2019, discovered Jan 4, 2019 — the first regulatory filing landed 42 days later. 120,000 individuals reported across the linked filings.
North Country Business Products, Inc. reported a data security incident where malware deployed to business partners' POS systems collected credit and debit card information (cardholder name, number, expiration, CVV) between Jan 3-24, 2019. The company engaged forensic investigators and notified affected parties and regulators.
North Country Business Products, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2019-02-15. The breach occurred during 1/3/2019 - 1/24/2019. The breach was discovered on 1/30/2019. 120,000 individuals were affected. Notice was sent on 2/15/2019.
Affected (this filing): 120,000
OR AG ≤45d
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.