HackingSkimmerCapture Stored DataCustomer Data InvolvedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Totally Reliable
bd_1c60e5c2cd51bcd7 · schema v1 · pii pii-v1
Full breach record for Totally Reliable →Totally Promotional experienced a data breach involving unauthorized code placed on its website's payment platform between November 20, 2023, and July 18, 2024. The code captured customer payment card information and names. The incident was discovered on July 10, 2024. The company removed the malicious code and adjusted policies. No specific count of affected individuals was disclosed in the notice, though Rhode Island residents were specifically mentioned.
California clockDiscovered Jul 10, 2024 → Notified Oct 16, 202498d ✗ CA 60-day late14 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0863f54abe165fa0New Hampshire State AGfiled 2024-10-16Verified
- bd_2fda4f5e88961d5aVermont State AGfiled 2024-10-16Verified
- bd_7ee71c6bd4ebf587Oregon State AGfiled 2024-10-16Candidate
- bd_815acf1458eb700cMontana State AGfiled 2024-10-16Verified by operator
Show 2 more filings ↓Show fewer ↑up to 40d gap
- bd_8eead9e4b3730fb0Indiana State AGfiled 2024-10-16Verified
- bd_8ddbfbb06d2cdce5California State AGfiled 2024-11-25(40d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-593446
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 16, 2024
- Raw hash
- b1090ebdd293e9aa01972664aa1cec8bc332e46df5e54c04cee25de8263e3b35
Reporting entity
- Name
- Totally Reliablenorm: totally reliable
- Domain
- totallyreliable.com
Victim entity
- Name
- Totally Reliablenorm: totally reliable
- Domain
- totallyreliable.com
Incident
- Discovered
- Jul 10, 2024
- Materiality determined
- —
- Notification sent
- Oct 16, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notifying relevant regulators as required
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- CA 60-day late · 98d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 10, 2024→ Notified: Oct 16, 202498d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.