Skip to content

Bombas

Disclosed Jun 6, 20197 years ago39,561 affectedSettled

Official notice

Card skimmer hit 39,561 customers, unnotified for 3 years; USD 65,000 NY AG penalty

On September 27, 2014 intruders inserted card-stealing code into Bombas' Magento storefront; Bombas found it that November but did not fully remove it until February 2015 and failed to notify 39,561 consumers for over three years. It paid USD 65,000 in penalties.

What is known

People affected39,561 (as reported by the organization)
DisclosedJun 6, 2019
DiscoveredDec 26, 2018
HappenedNov 11, 2016
AttackHacking
Data exposedPayment cards, Names, Addresses, Financial
SectorRetail · US
StatusSettled
Lawsuit or fineUSD 65,000 NY AG penalty (June 2019) (about $65K)

Sources

Source
California Attorney General breach notice: Bombasoag.ca.gov · Official notice
Washington Attorney General breach notice: Bombasatg.wa.gov · Official notice
Oregon DOJ breach notice: Bombasjustice.oregon.gov · Official notice
NY AG: USD 65,000 settlement with Bombasag.ny.gov · Regulator
Indiana Attorney General 2020 data breach report: Bombasin.gov · Official notice
Maine Attorney General breach notice archive: Bombasmaine.gov · Official notice

Notices filed

WhereFiledPeople
ResearchtotalJun 6, 201939,561
California AGresidents of CAJun 3, 2020
Washington AGresidents of WAJun 3, 20202,313
Oregon DOJresidents of ORJun 3, 202083,000
Indiana AGresidents of INJun 3, 20201,728
Maine AGresidents of MEJun 3, 2020488

Other breaches at Bombas

BreachAffected
Disclosed May 18, 2018May 18, 20188 years ago41K
History of this record
  • 2026-09-25 · data_types: ["payment-card","names","addresses"] to ["payment-card","names","addresses","financial"] · backfill source
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-2020.pdf · backfill source
  • 2026-09-25 · status: confirmed to settled · seed source
  • 2026-09-25 · fine_usd: empty to 65000 · seed source
  • 2026-09-25 · lawsuit: empty to USD 65,000 NY AG penalty (June 2019) · seed source
  • 2026-09-25 · sector: other to retail · seed source
  • 2026-09-25 · data_types: [] to ["payment-card","names","addresses"] · seed source
  • 2026-09-25 · records_basis: empty to organization · seed source
  • 2026-09-25 · records: empty to 39561 · seed source
  • 2026-09-25 · disclosed: 2020-06-03 to 2019-06-06 · seed source
  • 2026-09-25 · summary: empty to On September 27, 2014 intruders inserted card-stealing code into Bombas' Magento storefront; Bombas found it that November but did not fully remove it until February 2015 and failed to notify 39,561 consumers for over three years. It paid U · seed source
  • 2026-09-25 · title: empty to Card skimmer hit 39,561 customers, unnotified for 3 years; USD 65,000 NY AG penalty · seed source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · discovered: empty to 2018-12-26 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Bombas

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.