HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Farmgirl Flowers, Inc.
bd_0d81ec34c50e9b1e · schema v1 · pii pii-v1
Full breach record for Farmgirl Flowers, Inc. →Farmgirl Flowers, Inc. reported a data breach affecting customers between April 26 and April 29, 2018. Unauthorized access was gained by inserting rogue code into the company's checkout page, which captured customer names, billing addresses, phone numbers, emails, and credit card details (including CVV). The company notified the FBI and local law enforcement, implemented whitelist-based access controls, and deployed a more robust intrusion detection system. Affected customers were offered 24 months of identity protection services.
California clockDiscovered Apr 29, 2018 → Notified May 11, 201811d ✓ CA 60-day OK11 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_15ddfbc4f3b1d12cMontana State AGfiled 2018-05-09(2d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136114
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 11, 2018
- Raw hash
- 84225d8d3b8f04b1a0ed00f155cada5c3287bad901bb8e5d69b38f6dd2365f2b
Reporting entity
- Name
- Farmgirl Flowers, Inc.norm: farmgirl flowers
- Domain
- farmgirlflowers.com
Victim entity
- Name
- Farmgirl Flowers, Inc.norm: farmgirl flowers
- Domain
- farmgirlflowers.com
Incident
- Discovered
- Apr 29, 2018
- Materiality determined
- —
- Notification sent
- May 11, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI and local law enforcement in San Francisco, California
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 days(11 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 11d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 29, 2018→ Notified: May 11, 201811d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.