Bombas
Disclosed Jun 6, 20197 years ago39,561 affectedSettled
Card skimmer hit 39,561 customers, unnotified for 3 years; USD 65,000 NY AG penalty
On September 27, 2014 intruders inserted card-stealing code into Bombas' Magento storefront; Bombas found it that November but did not fully remove it until February 2015 and failed to notify 39,561 consumers for over three years. It paid USD 65,000 in penalties.
What is known
| People affected | 39,561 (as reported by the organization) |
|---|---|
| Disclosed | Jun 6, 2019 |
| Discovered | Dec 26, 2018 |
| Happened | Nov 11, 2016 |
| Attack | Hacking |
| Data exposed | Payment cards, Names, Addresses, Financial |
| Sector | Retail · US |
| Status | Settled |
| Lawsuit or fine | USD 65,000 NY AG penalty (June 2019) (about $65K) |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Bombasoag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: Bombasatg.wa.gov · Official notice | Official notice |
| Oregon DOJ breach notice: Bombasjustice.oregon.gov · Official notice | Official notice |
| NY AG: USD 65,000 settlement with Bombasag.ny.gov · Regulator | Regulator |
| Indiana Attorney General 2020 data breach report: Bombasin.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: Bombasmaine.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jun 6, 2019 | 39,561 |
| California AGresidents of CA | Jun 3, 2020 | |
| Washington AGresidents of WA | Jun 3, 2020 | 2,313 |
| Oregon DOJresidents of OR | Jun 3, 2020 | 83,000 |
| Indiana AGresidents of IN | Jun 3, 2020 | 1,728 |
| Maine AGresidents of ME | Jun 3, 2020 | 488 |
Other breaches at Bombas
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed May 18, 2018May 18, 20188 years ago | May 18, 20188 years ago | Not stated | Retail | Confirmed | 41K |
History of this record
- 2026-09-25 · data_types: ["payment-card","names","addresses"] to ["payment-card","names","addresses","financial"] · backfill source
- 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-2020.pdf · backfill source
- 2026-09-25 · status: confirmed to settled · seed source
- 2026-09-25 · fine_usd: empty to 65000 · seed source
- 2026-09-25 · lawsuit: empty to USD 65,000 NY AG penalty (June 2019) · seed source
- 2026-09-25 · sector: other to retail · seed source
- 2026-09-25 · data_types: [] to ["payment-card","names","addresses"] · seed source
- 2026-09-25 · records_basis: empty to organization · seed source
- 2026-09-25 · records: empty to 39561 · seed source
- 2026-09-25 · disclosed: 2020-06-03 to 2019-06-06 · seed source
- 2026-09-25 · summary: empty to On September 27, 2014 intruders inserted card-stealing code into Bombas' Magento storefront; Bombas found it that November but did not fully remove it until February 2015 and failed to notify 39,561 consumers for over three years. It paid U · seed source
- 2026-09-25 · title: empty to Card skimmer hit 39,561 customers, unnotified for 3 years; USD 65,000 NY AG penalty · seed source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · discovered: empty to 2018-12-26 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.