HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Agoura Health Products, LLC
bd_151b7361f0b238bd · schema v1 · pii pii-v1
Full breach record for Agoura Health Products, LLC →Agoura Health Products, LLC (dba Gundry MD) disclosed a data breach involving its payment processor, 1ShoppingCart. An unauthorized third party accessed 1ShoppingCart's systems between August 6, 2020, and August 22, 2020, potentially obtaining customer names, addresses, phone numbers, emails, and payment card details (including CVV). The breach was discovered on October 30, 2020. Gundry MD notified affected individuals and worked with 1ShoppingCart to assess the scope. No identity theft was confirmed.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e3ab1886f9b4b191Maine State AGfiled 2020-12-17Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197272
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 17, 2020
- Raw hash
- fc49dc92c3717f69dc487cbfa5d3570f3b4efa77906a7e882f69709e2789535b
Reporting entity
- Name
- Agoura Health Products, LLCnorm: agoura health products
Victim entity
- Name
- Agoura Health Products, LLCnorm: agoura health products
Incident
- Discovered
- Oct 30, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via 1ShoppingCart
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.