HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Rennline Automotive
bd_180cdb49baa54e75 · schema v1 · pii pii-v1
Full breach record for Rennline Automotive →Rennline Automotive experienced a data breach involving unauthorized code injected into its e-commerce website (rennline.com). The code, active between May 2018 and January 2019, copied and exfiltrated payment card information (including CVV) to an unauthorized server. The company engaged a cybersecurity firm, removed the code, and implemented a more secure checkout method. Affected data includes names, addresses, and financial account details.
California clockDiscovered Jan 18, 2019 → Notified Jan 18, 20190d ✓ CA 60-day OK5 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144918
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 21, 2019
- Raw hash
- 70c32b56c1e9a953feb479939c3162f456d7f1e6ee5a000e144f0082abdf3300
Reporting entity
- Name
- Rennline Automotivenorm: rennline automotive
- Domain
- rennline.com
Victim entity
- Name
- Rennline Automotivenorm: rennline automotive
- Domain
- rennline.com
Incident
- Discovered
- Jan 18, 2019
- Materiality determined
- —
- Notification sent
- Jan 18, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 18, 2019→ Notified: Jan 18, 20190d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.