HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Quality CPR Care LLC
bd_233144518da5e8e4 · schema v1 · pii pii-v1
Full breach record for Quality CPR Care LLC →Quality CPR Care LLC (dba American CPR Care Association) experienced an external system breach between June 1 and November 15, 2020, discovered on January 15, 2021. The incident affected 13,689 individuals, including 41 Maine residents. The breach involved the unauthorized acquisition of names and financial account or credit/debit card numbers (including security codes/PINs). The entity notified consumers in writing on March 15, 2021, but did not offer identity theft protection services.
Maine clockDiscovered Jan 15, 2021 → Filed with AG Mar 15, 202159d ⏱ ME AG >30d8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_7ff0e95a00b22f79Oregon State AGfiled 2021-03-15Verified
- bd_877385644bfbf0b5California State AGfiled 2021-03-15Verified
- bd_d9c9762db05b94a3Montana State AGfiled 2021-03-15Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/224bd776-be9f-487d-bc10-c91e2921bf17.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 15, 2021
- Raw hash
- 1775c8005a9642c0542921781782549de25d7e976567d85c105fe32d04c5654b
Reporting entity
- Name
- Quality CPR Care LLCnorm: quality cpr care
- Domain
- cpraedcourse.com
Victim entity
- Name
- Quality CPR Care LLCnorm: quality cpr care
- Domain
- cpraedcourse.com
Incident
- Discovered
- Jan 15, 2021
- Materiality determined
- —
- Notification sent
- Mar 15, 2021
- Affected individuals
- 13,689
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- ME AG >30d · 59d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 15, 2021→ Filed with AG: Mar 15, 202159d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.