HackingStolen CredentialsCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
THIRTY-ONE GIFTS LLC
bd_281dbdc514c69a60 · schema v1 · pii pii-v1
Full breach record for THIRTY-ONE GIFTS LLC →Thirty One Gifts LLC (TOG) notified affected individuals of a data security incident on July 21, 2023, where an unauthorized third party captured credit card information entered on mythirtyone.com. TOG engaged its incident response team, worked with law enforcement, and notified credit card brands. Affected individuals are offered two years of identity monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_284c08b308c7fadaIdaho State AGfiled 2023-08-25(2d gap)Candidate
- bd_e01ab103241e465cMontana State AGfiled 2023-08-25(2d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/SAMPLE-ELN-18930-Thirty-One-Gifts-Ad-CM-r5prf.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 27, 2023
- Raw hash
- ae66aad1aba9cf33978482e6b8490ee7add98e5da8ddbfcbffea581cbe925a91
Reporting entity
- Name
- TOG Holding Co.norm: tog holding
Victim entity
- Name
- THIRTY-ONE GIFTS LLCnorm: thirty one gifts
- Domain
- mythirtyone.com
Incident
- Discovered
- Jul 21, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.