HackingRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedPIIFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
RM Acquisition, LLC
bd_04d21df1ad5ac628 · schema v1 · pii pii-v1
Full breach record for RM Acquisition, LLC →RM Acquisition, LLC d/b/a Rand McNally experienced a data breach involving its e-commerce server. Between April 12, 2016, and March 2, 2017, an unauthorized party installed malware to collect customer credit card and personal information. The breach was discovered on April 11, 2017. Affected data includes billing/shipping addresses, cardholder names, card numbers, and CVVs. Rand McNally engaged forensic investigators, removed the malware, and offered one year of complimentary identity monitoring and restoration services through Experian to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0c088de827cae294Oregon State AGfiled 2017-05-05Verified
- bd_e46d73878171e112Montana State AGfiled 2017-05-05Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-68604
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 5, 2017
- Raw hash
- b7c672a416b0d0eca64e5fd0ff9031b8dcc55b798cb2bf476e3436bfa0a076df
Reporting entity
- Name
- RM Acquisition, LLCnorm: rm acquisition
Victim entity
- Name
- RM Acquisition, LLCnorm: rm acquisition
Incident
- Discovered
- Apr 11, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.