HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Tommie Copper
bd_19476cf9a1fafba3 · schema v1 · pii pii-v1
Full breach record for Tommie Copper →Tommie Copper Inc reported a data security incident involving unauthorized access to customer payment information via malware on its ecommerce website. The breach affected approximately 2,078 California residents between November 10, 2017, and January 22, 2018. Exposed data included names, addresses, phone numbers, emails, and credit/debit card details (including CVVs). Tommie Copper retained forensic investigators, removed the malware, and enhanced security controls, notifying affected individuals and regulators.
California clockDiscovered Jun 1, 2018 → Notified Jul 11, 201840d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3efb04bbd2966116Montana State AGfiled 2018-07-11Candidate
- bd_b64fa8601bc5d536Oregon State AGfiled 2018-07-11Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-137818
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 11, 2018
- Raw hash
- 81f06947edf6c1a890e68aa7a40ec2d61fc72d895bf091c2811dbdaed5a24018
Reporting entity
- Name
- Tommie Coppernorm: tommie copper
Victim entity
- Name
- Tommie Coppernorm: tommie copper
Incident
- Discovered
- Jun 1, 2018
- Materiality determined
- —
- Notification sent
- Jul 11, 2018
- Affected individuals
- 2,078
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided notice to other state regulators as required
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 40d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 1, 2018→ Notified: Jul 11, 201840d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.