MalwareRansomwareData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
St. Paul Center for Biblical Theology
bd_052fed53e72f2142 · schema v1 · pii pii-v1
Full breach record for St. Paul Center for Biblical Theology →St. Paul Center for Biblical Theology experienced a data security incident where malware installed in website software scraped payment card data from customers who made purchases or donations between March 3, 2020, and August 9, 2020. The incident involved unauthorized acquisition of names, addresses, emails, phone numbers, and payment card details including CVV codes. The organization corrected the vulnerability and conducted an internal audit.
California clockDiscovered Aug 20, 2020 → Notified Oct 2, 202043d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194694
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 2, 2020
- Raw hash
- e0d9b84c59b948610d76f8dfcc5efa6e6ee9da80c705243555ff9495137a9ffa
Reporting entity
- Name
- St. Paul Center for Biblical Theologynorm: st paul center for biblical theology
- Domain
- stpaulcenter.com
Victim entity
- Name
- St. Paul Center for Biblical Theologynorm: st paul center for biblical theology
- Domain
- stpaulcenter.com
Incident
- Discovered
- Aug 20, 2020
- Materiality determined
- —
- Notification sent
- Oct 2, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- providing notice of this incident to appropriate state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(43 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 43d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 20, 2020→ Notified: Oct 2, 202043d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.