HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Hoosier Racing Tire Corporation
bd_1e9e57ceccd464be · schema v1 · pii pii-v1
Full breach record for Hoosier Racing Tire Corporation →Hoosier Racing Tire Corporation notified consumers of a data breach involving unauthorized code installed on its vendor-managed ecommerce site between Nov 2020 and Sep 2022. The code may have captured personal information including names, payment card numbers, expiration dates, and CVVs. Hoosier discovered the incident on March 9, 2023, engaged forensic investigators, notified law enforcement, and is offering 24 months of identity theft protection services to affected individuals.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_7455fe533175010dNew Hampshire State AGfiled 2023-04-14Verified
- bd_a29b8f8229f16f10Maine State AGfiled 2023-04-14Candidate
- bd_f3b47d19c1b7f40dMontana State AGfiled 2023-04-14Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-04-14-hoosier-racing-tire-corporation-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 14, 2023
- Raw hash
- 4aff65b2d8ab0c0622d32dde0f4d671c4cda6ad58043168cf6e8025f2b62cb42
Reporting entity
- Name
- Hoosier Racing Tire Corporationnorm: hoosier racing tire
Victim entity
- Name
- Hoosier Racing Tire Corporationnorm: hoosier racing tire
Incident
- Discovered
- Mar 9, 2023
- Materiality determined
- Mar 9, 2023
- Notification sent
- Apr 14, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- supply_chain
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.