HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
BEL USA LLC
bd_1b22d8ec0a32e0f4 · schema v1 · pii pii-v1
Full breach record for BEL USA LLC →BEL USA, LLC (DiscountMugs.com) disclosed a data breach where unauthorized code was inserted into its shopping cart page, collecting customer PII and payment card details (including CVV2). The incident affected orders placed between August 5, 2018, and November 16, 2018. The company retained a security firm, removed the code, and notified law enforcement and payment card companies. Affected customers were offered 12 months of identity protection via AllClear ID.
California clockDiscovered Nov 16, 2018 → Notified Dec 20, 201834d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_ccae1af0c49f26e9Washington State AGfiled 2018-12-26Candidate
- bd_2fe11865ef1e5141Montana State AGfiled 2018-12-31(5d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-143174
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 26, 2018
- Raw hash
- 662a7b8f1ee0eb5738d946225ab7487613334faab79ca59315d6005d94f96a3d
Reporting entity
- Name
- BEL USA LLCnorm: bel usa
- Domain
- discountmugs.com
Victim entity
- Name
- BEL USA LLCnorm: bel usa
- Domain
- discountmugs.com
Incident
- Discovered
- Nov 16, 2018
- Materiality determined
- —
- Notification sent
- Dec 20, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the matter to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 34d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 16, 2018→ Notified: Dec 20, 201834d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.