HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
IM Shopping, Inc.
bd_08ccb4f9267d0727 · schema v1 · pii pii-v1
Full breach record for IM Shopping, Inc. →IM Shopping, Inc. reported a data breach affecting its Gift Card Mall website. An unauthorized script was injected into the site code between April 24, 2019, and discovered on May 21, 2019. The script exfiltrated consumer name, address, and payment card details (including CVV) to an external site. IM Shopping engaged a cybersecurity firm, removed the script, and logged out affected users. They provided 24 months of credit monitoring and identity protection services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148456
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2019
- Raw hash
- fc1cd314063d6f03f6f92805d69aabdfe88de175a784ea9d0fb7ea56d0c9587c
Reporting entity
- Name
- IM Shopping, Inc.norm: im shopping
Victim entity
- Name
- IM Shopping, Inc.norm: im shopping
Incident
- Discovered
- May 21, 2019
- Materiality determined
- Jun 14, 2019
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.