HackingVulnerability ExploitCapture Stored DataCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
Squishable.com, Inc.
bd_16ee5ba23e9a9e21 · schema v1 · pii pii-v1
Full breach record for Squishable.com, Inc. →Squishable.com, Inc. notified consumers of a data breach where unauthorized code on its checkout page allowed a third party to capture customer information, including names, addresses, payment card details, and email addresses, between May 26 and October 12, 2022. The company engaged forensic investigators, notified law enforcement, and updated its infrastructure.
Vermont clock✗ VT AG >45 bday20 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_067484bba6b3d128Washington State AGfiled 2023-03-02Candidate
- bd_26dc2eee49c486e4Montana State AGfiled 2023-03-06(4d gap)Verified by operator
- bd_64f8fc08e15e855bNew Hampshire State AGfiled 2023-03-06(4d gap)Verified
- bd_6bd9ef85cda292c9Maine State AGfiled 2023-03-06(4d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 4d gap
- bd_c0b7238b2f2d673bCalifornia State AGfiled 2023-03-06(4d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-03-02-squishablecom-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2023
- Raw hash
- a7c79fd2a59bfe31866662d38b6226a043dc27b6c56b7965434cd13002f1f6b7
Reporting entity
- Name
- Squishable.com, Inc.norm: squishablecom
- Domain
- squishable.com
Victim entity
- Name
- Squishable.com, Inc.norm: squishablecom
- Domain
- squishable.com
Incident
- Discovered
- Oct 12, 2022
- Materiality determined
- —
- Notification sent
- Mar 2, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(141 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.