HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Savory Spice
bd_0c7c66767f2a2989 · schema v1 · pii pii-v1
Full breach record for Savory Spice →Savory Spice, a retail merchant, disclosed a data breach affecting its online store. Unauthorized parties accessed customer purchase information between April 5, 2018, and March 27, 2021. The incident involved the exposure of names and payment card details (numbers, expiration, security codes). Savory Spice engaged third-party forensic investigators and implemented enhanced payment security measures. The breach was discovered in October 2020 and concluded in July 2021.
California clockDiscovered Oct 8, 2020 → Notified Jul 14, 2021279d ✗ CA 60-day late41 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0beb87862b2f7398Washington State AGfiled 2021-07-23Candidate
- bd_7eb58b730b59235fMaine State AGfiled 2021-07-23Verified by operator
- bd_85c9d799dcc70cbaOregon State AGfiled 2021-07-23Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-543203
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 23, 2021
- Raw hash
- adb944bde200846eeef0923f82bed06a7659f1ac6ece2962d74134be1978133c
Reporting entity
- Name
- Savory Spicenorm: savory spice
Victim entity
- Name
- Savory Spicenorm: savory spice
Incident
- Discovered
- Oct 8, 2020
- Materiality determined
- Jul 14, 2021
- Notification sent
- Jul 14, 2021
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 41 weeks(288 days from discovery to filing)
- Compliance flags
- CA 60-day late · 279d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 8, 2020→ Notified: Jul 14, 2021279d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.