HackingStolen CredentialsCustomer Data InvolvedPCIFINANCIAL_ACCOUNTPIILowContained
Aventist Media Center
bd_109329873e5437eb · schema v1 · pii pii-v1
Full breach record for Aventist Media Center →Adventist Media Center d/b/a It Is Written notified the NH AG of a breach affecting 1 NH resident. Malicious code capturing payment card data was injected into the retail website via compromised external access credentials. Incident window: Feb 8 - Mar 23, 2023. Notification sent May 5, 2023.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_947fc5a5f0259adeMontana State AGfiled 2023-05-16(1d gap)Verified by operator
- bd_2181b81b0441bdabMaine State AGfiled 2023-05-08(7d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/adventist-media-center-dba-it-is-written-20230515.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 15, 2023
- Raw hash
- f34967c3bc7335b72380ca5233762f23163499705062efc8223284a78f4598c2
Reporting entity
- Name
- Aventist Media Centernorm: aventist media center
Victim entity
- Name
- Aventist Media Centernorm: aventist media center
Incident
- Discovered
- Mar 23, 2023
- Materiality determined
- Apr 18, 2023
- Notification sent
- May 5, 2023
- Affected individuals
- 1
- Data types
- PCIFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.