Clustered 6 filings across 6 jurisdictions · filing window Aug 2, 2022 → Aug 19, 2022. View entity profile → Other incidents for this victim →
incident inc_5a66f603763c4460 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Financial account
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA DE ME NH OR WA
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Sep 18, 2020 → Feb 3, 2022
When the intrusion reportedly occurred, per the linked filings
Aug 2, 2022
Reported by DELAWARE AG, CALIFORNIA AG, MAINE AG, WASHINGTON AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Sturm, Ruger & Company, Inc. notified customers that its third-party payment vendor, Freestyle Solutions, experienced a data breach. Malware on the Freestyle server hosting ShopRuger.com captured customer payment card data, names, and addresses between September 2020 and February 2022. Ruger engaged Verizon for forensics, notified law enforcement, and offered 12 months of identity protection services. No evidence of improper use was found.
Sturm, Ruger & Company, Inc. disclosed a data breach involving its third-party payment processor, Freestyle Solutions. Malware on Freestyle's server captured customer payment card information and PII from ShopRuger.com between September 18, 2020, and February 3, 2022. Sturm, Ruger engaged Verizon for forensic investigation, notified law enforcement, and offered 12 months of identity theft protection to affected individuals.
Sturm, Ruger & Company, Inc. reported a data breach caused by malware that affected 167,963 individuals. The breach occurred between September 18, 2020, and February 3, 2022, and was discovered on August 2, 2022. The compromised information included names and financial account or credit/debit card numbers with their corresponding access codes. The company provided written notification to affected individuals on August 18, 2022, and offered 12 months of identity theft protection services.
Affected (this filing): 167,963
Sturm, Ruger & Company, Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2022-08-17. The breach occurred during 1/1/0001. 167,963 individuals were affected.
Affected (this filing): 167,963
Sturm, Ruger & Company, Inc., a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2022-08-02 and filed notice on 2022-08-18. 4,866 Washington residents were affected. 16 days elapsed between awareness and notification. 683 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 4,866
Sturm, Ruger & Company, Inc. notified the New Hampshire Attorney General of a data breach affecting approximately 1,639 New Hampshire residents. The incident involved unauthorized access to ShopRuger.com, hosted by third-party vendor Freestyle Solutions. Customer PII was potentially compromised. The breach occurred at the third-party vendor's server.
Affected (this filing): 1,639