HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Kroto Inc.
bd_03ef69d061959362 · schema v1 · pii pii-v1
Full breach record for Kroto Inc. →Kroto Inc. d/b/a iCanvas disclosed a data breach involving unauthorized scripts placed on its checkout page between May 10 and May 28, 2020. The script captured customer payment card numbers, security codes, and personal information. The company removed the script, notified law enforcement, and provided one year of complimentary credit monitoring via TransUnion.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-191341
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 24, 2020
- Raw hash
- 0045f51c79162e91624f669d227115fa5121548f287b8aa6b46d9ea4bddb06bf
Reporting entity
- Name
- Kroto Inc.norm: kroto
- Domain
- icanvas.com
Victim entity
- Name
- Kroto Inc.norm: kroto
- Domain
- icanvas.com
Incident
- Discovered
- May 28, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.