HackingSkimmerCapture App DataCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCILowResolved
California Massage Therapy Council
bd_1e06efde36f08fc9 · schema v1 · pii pii-v1
Full breach record for California Massage Therapy Council →California Massage Therapy Council (CAMTC) notified individuals of a potential data security incident involving its online payment page. CAMTC learned of the incident on February 22, 2021. The incident potentially exposed names, addresses, payment card numbers, expiration dates, and card security codes. CAMTC took its payment page offline, engaged a forensic firm, and migrated to a new payment platform. The occurrence date reported was November 4, 2020.
California clockDiscovered Feb 22, 2021 → Notified Aug 26, 2021185d ✗ CA 60-day late28 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_9c5fa93deaaab850Maine State AGfiled 2021-09-08Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-545053
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 8, 2021
- Raw hash
- d7a561fcd87733f42a1948f187d7233c90c0cb2b737daa1f635e8fdbacc334e1
Reporting entity
- Name
- California Massage Therapy Councilnorm: california massage therapy council
- Domain
- camtccms.inlumon.com
Victim entity
- Name
- California Massage Therapy Councilnorm: california massage therapy council
- Domain
- camtccms.inlumon.com
Incident
- Discovered
- Feb 22, 2021
- Materiality determined
- —
- Notification sent
- Aug 26, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 weeks(198 days from discovery to filing)
- Compliance flags
- CA 60-day late · 185d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 22, 2021→ Notified: Aug 26, 2021185d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.