HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
MTG USA, Inc.
bd_0018a6255b8b67f8 · schema v1 · pii pii-v1
Full breach record for MTG USA, Inc. →MTG USA, Inc. reported a data security incident on its website www.ReFaUSA.com occurring between June 25, 2020, and June 15, 2021. The breach potentially exposed payment card information, names, and addresses. MTG suspended transactions, moved the server offline, and engaged forensic specialists. No evidence of misuse was found, but the company offered two years of Experian IdentityWorks to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3a8167a3ce491ba0Maine State AGfiled 2021-09-22(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-545757
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2021
- Raw hash
- b88a66b6ba8839285a08556577773e74db53a1f435a890e8afba6eceb900be23
Reporting entity
- Name
- MTG USA, Inc.norm: mtg usa
Victim entity
- Name
- MTG USA, Inc.norm: mtg usa
Incident
- Discovered
- Sep 9, 2021
- Materiality determined
- Sep 21, 2021
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.