HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATIONLowContained
Thorlo
bd_0516eac2bfdb95e8 · schema v1 · pii pii-v1
Full breach record for Thorlo →Thorlo, an online retailer, disclosed a cybercrime incident where hackers intercepted customer data, including names, contact info, and credit card numbers (including expiration dates and security codes), during transaction processing. The breach affected customers who made purchases on thorlo.com between November 14, 2012, and January 22, 2013. Thorlo reported the incident to the FBI and local police, engaged Kroll Information Assurance for identity theft safeguards, and secured its website.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-38841
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 7, 2013
- Raw hash
- 2d7dd615182b02a0202ecf71fface59e25fcb65096675d77c5c15bd0030d5fbe
Reporting entity
- Name
- Thorlonorm: thorlo
- Domain
- thorlo.com
Victim entity
- Name
- Thorlonorm: thorlo
- Domain
- thorlo.com
Incident
- Discovered
- Jan 22, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- filed reports with the FBI Cyber Crimes Unit
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.