HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Churchill Downs Technology Initiatives Company
bd_0d4193f5e689eaef · schema v1 · pii pii-v1
Full breach record for Churchill Downs Technology Initiatives Company →Churchill Downs Technology Initiatives Company reported an external system breach (hacking) occurring between September 5, 2020, and October 2, 2020. The incident compromised the personal information of 950 individuals, including 4 Maine residents. Acquired data included names combined with financial account or credit/debit card numbers (including security codes, access codes, passwords, or PINs). The company provided written notification to affected consumers on October 30, 2020.
Maine clockDiscovered Oct 2, 2020 → Filed with AG Oct 30, 202028d ✓ ME AG ≤30d28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed950 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/23096b8f-685f-4e4f-bd76-2f380f522802.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 30, 2020
- Raw hash
- 3292f59b6ca2497aeb4f0459ae006cc273cde58c99f670fbc79875d3ca44bfcb
Reporting entity
- Name
- Churchill Downs Technology Initiatives Companynorm: churchill downs technology initiatives
Victim entity
- Name
- Churchill Downs Technology Initiatives Companynorm: churchill downs technology initiatives
Incident
- Discovered
- Oct 2, 2020
- Materiality determined
- —
- Notification sent
- Oct 30, 2020
- Affected individuals
- 950
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 28d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Oct 2, 2020→ Filed with AG: Oct 30, 202028d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.