Clustered 11 filings across 9 jurisdictions · filing window Oct 7, 2024 → Oct 31, 2024. View entity profile → Other incidents for this victim →
incident inc_53a297fc50d64950 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Financial account · Financial credentials
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA DE IN ME MT NH OR VT
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
11 filings across 9 jurisdictions · Oct 7, 2024 – Oct 31, 2024 · 2 milestones
Jan 7, 2024
When the intrusion reportedly occurred, per the linked filings
Sep 28, 2024
Reported by DELAWARE AG, VERMONT AG, NEW HAMPSHIRE AG, CALIFORNIA AG, OREGON AG, MAINE AG, WASHINGTON AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
SelectBlinds notified affected individuals of a data breach where malware was embedded on its website starting January 7, 2024, allowing unauthorized scraping of checkout data. The incident was discovered on September 28, 2024. Compromised data included names, addresses, phone numbers, and payment card details (including CVV). SelectBlinds contained the incident, engaged external experts, and locked user accounts.
SelectBlinds notified consumers of a data breach where malware embedded on its website scraped transaction data from January 7, 2024, through September 28, 2024. Affected data included names, addresses, payment card details (including CVV), and credentials. SelectBlinds engaged external experts, contained the incident, and locked user accounts. No specific total affected count was disclosed in the filing.
SelectBlinds, an Arizona-based online retailer, experienced an external system breach (hacking) that began on January 7, 2024 and was discovered on September 28, 2024. The breach affected 206,238 individuals total, including 1,185 Maine residents. Consumer notifications were sent on October 31, 2024. No identity theft protection services were offered.
Affected (this filing): 1,185
SelectBlinds notified consumers of a data breach where malware was embedded on its website starting Jan 7, 2024, allowing data scraping of checkout transactions. The incident was discovered on Sept 28, 2024. Compromised data included names, addresses, phone numbers, and payment card details (number, expiration, CVV). SelectBlinds contained the incident, removed malware, and locked user accounts.
SelectBlinds, an online retailer of custom window coverings, disclosed a data breach occurring on or about January 7, 2024, discovered on September 28, 2024. An unauthorized third party embedded malware on the SelectBlinds website to scrape sales transaction data from the checkout page. Affected data included names, emails, shipping/billing addresses, phone numbers, and payment card information (number, expiration, CVV). The incident was contained, malware eradicated, and notifications sent on October 31, 2024, to affected individuals, including 815 Rhode Island residents.
SelectBlinds reported a data breach to the Montana Attorney General. The breach was reported on 2024-10-31. The breach occurred from 1/7/2024 to 9/28/2024. 1,416 Montana residents were affected.
Affected (this filing): 1,416
SelectBlinds reported a data breach to the Indiana Attorney General. The breach occurred on 2024-01-07 and was reported on 2024-10-31. 2,140 Indiana residents were affected. 206,238 individuals affected in total.
Affected (this filing): 206,238
SelectBlinds notified the NH AG and ~1,206 residents of a data security incident. Beginning Jan 7, 2024, malware was embedded on the checkout page to scrape transaction data. SelectBlinds detected unusual activity on Sep 28, 2024, and completed an investigation on Oct 10, 2024. Affected data includes personal and payment information. SelectBlinds locked user accounts, engaged forensic experts, and notified law enforcement.
Affected (this filing): 1,206
SelectBlinds, an online retailer of custom window coverings, experienced a data breach beginning on or about January 7, 2024. An unauthorized third party embedded malware on the SelectBlinds website, allowing data scraping of sales transactions entered on the checkout page. The company became aware of the incident on September 28, 2024. Affected data includes names, emails, shipping/billing addresses, phone numbers, payment card numbers, expiration dates, CVV codes, and potentially usernames/passwords. The incident was contained, malware eradicated, and user accounts temporarily locked. No specific count of affected individuals was disclosed in the provided notice samples.
SelectBlinds reported a data breach to the Oregon Attorney General. The breach was reported on 2024-10-31. The breach occurred during 1/7/2024 - 9/28/2024. The breach was discovered on 9/28/2024. 206,238 individuals were affected. Notice was sent on 10/31/2024.
Affected (this filing): 206,238
SelectBlinds, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2024-09-28 and filed notice on 2024-10-31. 7,530 Washington residents were affected. 33 days elapsed between awareness and notification. 265 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 7,530