HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
JM BULLION, INC.
bd_11d6a84f940445f1 · schema v1 · pii pii-v1
Full breach record for JM BULLION, INC. →JM Bullion, Inc. reported a data breach affecting California residents. Malicious code was present on the company's website from February 18, 2020, to July 17, 2020, capturing customer name, address, and payment card information during purchases. The incident was discovered on July 6, 2020, and the malicious code was removed on July 17, 2020. The company engaged forensic specialists, notified law enforcement and card processors, and implemented additional website safeguards.
California clockDiscovered Jul 6, 2020 → Notified Jul 17, 202011d ✓ CA 60-day OK16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_106ec3e84198338aMaine State AGfiled 2020-10-28Candidate
- bd_3b8043eda4f0c12cOregon State AGfiled 2020-10-28Verified
- bd_caa168ab6727add3Washington State AGfiled 2020-10-28Verified
- bd_cb3bb40a791227cdMontana State AGfiled 2020-10-28Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-195631
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 28, 2020
- Raw hash
- 7978bc7d77b00fb4bf35f18f9157f5efd878786fbd5d702a62cfdf9cb06e011b
Reporting entity
- Name
- JM BULLION, INC.norm: jm bullion
Victim entity
- Name
- JM BULLION, INC.norm: jm bullion
Incident
- Discovered
- Jul 6, 2020
- Materiality determined
- —
- Notification sent
- Jul 17, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(114 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 11d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 6, 2020→ Notified: Jul 17, 202011d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.