On September 28, 2024, SelectBlinds, a leading online retailer specializing in custom-made window coverings, discovered a significant data breach. The breach occurred on January 7, 2024, when an unauthorized third party embedded malware on the company’s website. This malware enabled the attacker to scrape sensitive customer data entered on the checkout page.
The breach affected a total of 206,238 individuals across the United States. The compromised information included highly sensitive personal and financial data, such as:
The severity of the breach is notable, as the stolen data could potentially be used for identity theft, financial fraud, or unauthorized account access. The malware was active for an extended period before being detected, increasing the risk of exposure for affected individuals.
For residents in specific states, the number of impacted individuals is as follows:
SelectBlinds disclosed the breach to several state attorney general offices, including California, Maine, Massachusetts, South Carolina, and Texas between October 31, 2024, and November 1, 2024. Consumers were notified via written mail and email starting on October 31, 2024.
Upon discovering the breach, SelectBlinds launched an immediate investigation with the assistance of external cybersecurity experts. The company identified and eradicated the malware by October 10, 2024, and implemented several measures to prevent future incidents. These measures include:
These actions aim to minimize the risk of further unauthorized access and ensure the safety of customer information moving forward.
If you believe you may have been affected by this data breach, it is crucial to take immediate steps to protect your personal and financial information. Here’s what you should do:
By taking these steps, you can reduce the risk of identity theft and financial fraud resulting from the breach.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.