HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
SPRINT CAPITAL CORPORATION
bd_03fb61bc40e498f9 · schema v1 · pii pii-v1
Full breach record for SPRINT CAPITAL CORPORATION →Sprint Corporation notified South Carolina consumers of unauthorized access to customer accounts via the Samsung.com 'add a line' website. The breach involved account credentials used to access personal data including names, billing addresses, phone numbers, and financial account details. Sprint reset affected account PINs and secured accounts on June 25, 2019.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2019/Sprint.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2019
- Raw hash
- 18ebac7f49f1f6450b1a5b2b33419514b13ccc066598a512443cbbd829078b17
Reporting entity
- Name
- SPRINT CAPITAL CORPORATIONnorm: sprint capital
Victim entity
- Name
- SPRINT CAPITAL CORPORATIONnorm: sprint capital
Incident
- Discovered
- Jun 22, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.