HackingBrute ForceCustomer Data InvolvedCREDENTIALSIDENTITY_BASICLowContained
The Shubert Organization, Inc.
bd_153b5f196c04631b · schema v1 · pii pii-v1
Full breach record for The Shubert Organization, Inc. →On January 19, 2026, The Shubert Organization, Inc. experienced a brute force attack on its Telecharge ticketing website by an unknown cyber actor. The attacker accessed certain user accounts. The organization secured the website, deactivated affected accounts, and conducted an investigation. Customers were notified on March 20, 2026, and advised to change passwords if reused elsewhere.
California clockConsumers notified Mar 20, 2026 → AG copy submitted Mar 20, 20260d ✓ CA AG copy ≤15d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_edd918dd46765435Vermont State AGfiled 2026-03-20Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-620613
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 20, 2026
- Raw hash
- 6fda5f011480d69d1f87192206ba4b2af1a22b7fcf1b6c4810d91760a2ebfcfa
Reporting entity
- Name
- The Shubert Organization, Inc.norm: the shubert organization
Victim entity
- Name
- The Shubert Organization, Inc.norm: the shubert organization
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Mar 20, 2026
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1110 Brute Force
- Threat actor
- External
Compliance
- Compliance flags
- CA AG copy ≤15d · 0d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status California Consumers notified: Mar 20, 2026→ AG copy submitted: Mar 20, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.