HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
SERRV International
bd_17e5ef2969179386 · schema v1 · pii pii-v1
Full breach record for SERRV International →SERRV International notified customers of a data security incident involving its third-party e-commerce platform, CommerceV3. An unauthorized party accessed CommerceV3 systems between November 24, 2021, and December 14, 2022. CommerceV3 identified potentially impacted SERRV customers on July 17, 2023. Affected data may include name, email, billing address, payment card number, expiration date, and security code. SERRV and CommerceV3 conducted forensic investigations and implemented additional security measures.
California clockDiscovered Jul 17, 2023 → Notified Aug 25, 202339d ✓ CA 60-day OK6 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_dfb5cf626154740cMontana State AGfiled 2023-08-28Verified
- bd_08ffdb5fb7d5760dNew Hampshire State AGfiled 2023-08-29(1d gap)Verified
- bd_c0397a66ed1f65a3Washington State AGfiled 2023-08-29(1d gap)Candidate
- bd_c3a7e9d559999fc5Oregon State AGfiled 2023-08-29(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_ed8988c26ba5160aMaine State AGfiled 2023-08-29(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572518
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2023
- Raw hash
- 1fde2f895766a3bc048dd692fef9a8a50e4228451446efbb96d711be49193666
Reporting entity
- Name
- SERRV Internationalnorm: serrv international
- Domain
- serrv.org
Victim entity
- Name
- SERRV Internationalnorm: serrv international
- Domain
- serrv.org
Incident
- Discovered
- Jul 17, 2023
- Materiality determined
- —
- Notification sent
- Aug 25, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via CommerceV3
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 39d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 17, 2023→ Notified: Aug 25, 202339d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.