HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Warner Music Group
bd_07f2cbb6b77f4ab8 · schema v1 · pii pii-v1
Full breach record for Warner Music Group →Warner Music Group (WMG) disclosed a cybersecurity incident involving its US-based e-commerce websites, hosted by an external service provider. Between April 25 and August 5, 2020, an unauthorized third party potentially acquired personal information entered by customers, including names, contact details, and payment card data (excluding PayPal transactions). WMG engaged forensic experts, notified law enforcement and credit card providers, and offered 12 months of free identity monitoring via Kroll.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_291443e8a8500296Montana State AGfiled 2020-09-02Verified
- bd_4c882e60c0727844California State AGfiled 2020-09-02Verified
- bd_adff23c1da81b497Washington State AGfiled 2020-09-02Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2020/WarnerMusicGroup.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 2, 2020
- Raw hash
- b9b67d6ae3df1901ce74bbb33c6916f5da720fde65f52c3a332958e44d1169ec
Reporting entity
- Name
- Warner Music Groupnorm: warner music
Victim entity
- Name
- Warner Music Groupnorm: warner music
Incident
- Discovered
- Aug 5, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.