HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Amateur Athletic Union
bd_188946594fb10928 · schema v1 · pii pii-v1
Full breach record for Amateur Athletic Union →The Amateur Athletic Union (AAU) disclosed a cybersecurity incident involving its website play.aausports.org. Between October 1, 2018, and July 2, 2019, malicious code captured payment card information (name, address, card number, expiration, CVV) from the checkout page. AAU identified the code on August 2, 2019, with forensic investigators, removed it, and notified regulators. The incident involved customer payment data.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_6abca2ac98691b14Hawaii State AGfiled 2019-09-13Verified
- bd_7dfeedd60232f38eOregon State AGfiled 2019-09-13Candidate
- bd_a145c79fea7b2b15Washington State AGfiled 2019-09-13Verified
- bd_b07fe0428d117bacMontana State AGfiled 2019-09-13Verified by operator
Show 1 more filing ↓Show fewer ↑
- bd_ef8c672acb9b8d2dCalifornia State AGfiled 2019-09-13Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2020/06/AAU-Sample-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 13, 2019
- Raw hash
- f97edaf40401475c4055771376d6d843e9fe65e315388bb9a1bc494c370ba6d6
Reporting entity
- Name
- Amateur Athletic Unionnorm: amateur athletic union
Victim entity
- Name
- Amateur Athletic Unionnorm: amateur athletic union
Incident
- Discovered
- Aug 2, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified required state regulatorsNotified consumer reporting agencies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.