HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
Nickey Performance
bd_1da50b7650d1a87f · schema v1 · pii pii-v1
Full breach record for Nickey Performance →Nickey Kehoe, Inc. disclosed a data security incident on March 29, 2026, involving unauthorized access to its email service provider, Klaviyo. The incident resulted in the exposure of customer names, email addresses, phone numbers, and postal addresses. No payment card, banking, or account credential data was accessed. The company removed compromised credentials and improved security protocols within 24 hours. The incident is contained.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-623979
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2026
- Raw hash
- 5ce9d07f935be400b4810a13a7c39ce73c6e166dc5360b4e44b97906c6e3609f
Reporting entity
- Name
- Nickey Performancenorm: nickey performance
- Domain
- nickeyperformance.com
Victim entity
- Name
- Nickey Performancenorm: nickey performance
- Domain
- nickeyperformance.com
Incident
- Discovered
- Mar 29, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Klaviyo
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.