HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Flinn Scientific, Inc.
bd_185d9c1f8514938c · schema v1 · pii pii-v1
Full breach record for Flinn Scientific, Inc. →Flinn Scientific, Inc. disclosed a cybersecurity incident affecting its internet store. A cyber-attacker used malware to access the server hosting the store between May 2, 2014, and September 8, 2014. The attacker intercepted payment card information (numbers, verification codes, expiration dates) along with customer names, addresses, and email addresses. Flinn Scientific eliminated the malware, blocked further access, and implemented additional security measures. Affected customers were offered 12 months of credit monitoring services through AllClear ID.
California clockDiscovered Sep 8, 2014 → Notified Oct 2, 201424d ✓ CA 60-day OK23 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c43b6893687c19d7New Hampshire State AGfiled 2014-10-01Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-46816
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 1, 2014
- Raw hash
- bef9a37844fe69765028cfb475b87a3e8348659290a9c586cfe4df3c4e44bf2c
Reporting entity
- Name
- Flinn Scientific, Inc.norm: flinn scientific
- Domain
- flinnsci.com
Victim entity
- Name
- Flinn Scientific, Inc.norm: flinn scientific
- Domain
- flinnsci.com
Incident
- Discovered
- Sep 8, 2014
- Materiality determined
- —
- Notification sent
- Oct 2, 2014
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 24d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 8, 2014→ Notified: Oct 2, 201424d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.