Clustered 5 filings across 5 jurisdictions · filing window Jun 2, 2024 → Jun 5, 2024. View entity profile → Other incidents for this victim →
incident inc_f471f84db3f54022 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · PII
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA ID ME NH VT
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
May 30, 2024
When the intrusion reportedly occurred, per the linked filings
May 30, 2024
Reported by VERMONT AG, IDAHO AG, NEW HAMPSHIRE AG, MAINE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Gapbuster Worldwide notified Vermont AG of a May 30, 2024 data breach involving third-party vendor Nectar Desk. Cloud storage containing mystery shoppers' names, emails, and mobile numbers was accessed. Incident contained; vendor tracking downloads to prevent further distribution.
Gapbuster Worldwide Pty Ltd (GBW) notified the Idaho Attorney General on June 4, 2024, regarding a data breach involving its third-party vendor, Nectar Desk. On May 30, 2024, GBW discovered that personal data of 140 independent contract employees (names, emails, mobile numbers, login details, shopper codes) was exposed on public AWS S3 storage due to Nectar's misconfigured storage policy. GBW notified Nectar, who contained the incident. GBW is notifying affected individuals and regulators.
Affected (this filing): 140
Gapbuster Worldwide Pty Ltd reported a data breach involving 57 independent contractors. The breach was caused by third-party vendor Nectar Desk, which erroneously exposed mystery shopper data on a public AWS S3 bucket after GBW ended its subscription. GBW detected the incident on May 30, 2024, and notified affected individuals on June 2, 2024.
Affected (this filing): 57
Gapbuster Worldwide Pty Ltd (GBW) reported a data security breach to the California Attorney General. The incident occurred on May 28, 2024. The filing provides minimal detail regarding the nature of the breach, data types affected, or number of individuals impacted.
Gapbuster Worldwide Pty Ltd (GBW) reported a data loss incident that occurred on May 28, 2024, and was discovered two days later. The incident affected 64,811 individuals in total, including 50 residents of Maine. Affected individuals were notified electronically on June 2, 2024. The specific types of information involved were not specified in the public notification.
Affected (this filing): 50