HackingVulnerability ExploitCustomer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
Totally Reliable
bd_0863f54abe165fa0 · schema v1 · pii pii-v1
Full breach record for Totally Reliable →Totally Promotional notified New Hampshire residents of a data breach involving payment card information. Suspicious activity was identified on July 10, 2024, involving unauthorized code placed on the website's payment platform between November 20, 2023, and July 18, 2024. The incident affected 155 New Hampshire residents. The company removed the malicious code and is providing fraud protection guidance.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1c60e5c2cd51bcd7California State AGfiled 2024-10-16Verified
- bd_2fda4f5e88961d5aVermont State AGfiled 2024-10-16Verified
- bd_7ee71c6bd4ebf587Oregon State AGfiled 2024-10-16Candidate
- bd_815acf1458eb700cMontana State AGfiled 2024-10-16Verified by operator
Show 2 more filings ↓Show fewer ↑up to 40d gap
- bd_8eead9e4b3730fb0Indiana State AGfiled 2024-10-16Verified
- bd_8ddbfbb06d2cdce5California State AGfiled 2024-11-25(40d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/totally-promotional-20241016.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 16, 2024
- Raw hash
- 788a1438c71ef489961e2dc464148e41a2a00d3106f1a9ecdbe323c4de99a98a
Reporting entity
- Name
- Totally Reliablenorm: totally reliable
- Domain
- totallyreliable.com
Victim entity
- Name
- Totally Reliablenorm: totally reliable
- Domain
- totallyreliable.com
Incident
- Discovered
- Jul 10, 2024
- Materiality determined
- Sep 13, 2024
- Notification sent
- Oct 16, 2024
- Affected individuals
- 155
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified relevant state regulatorsNotified the three major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.