Blundstone (U.S.A.) Inc. disclosed a data breach affecting customers who made online purchases. An unauthorized third party exploited a vulnerability in a plug-in on the Adobe Commerce (Magento) platform on November 12, 2024, to install malicious code that duplicated the checkout page. The attacker collected personal and payment information, including names, addresses, phone numbers, and payment card details with CVVs, for a period of 2.5 hours. Blundstone removed the malicious code, applied security patches, and engaged outside cybersecurity and legal counsel.