HackingVulnerability ExploitCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
Artifact Uprising
bd_281f8ed31c66f50d · schema v1 · pii pii-v1
Full breach record for Artifact Uprising →SPAU Holdings, LLC d/b/a Artifact Uprising LLC notified the NH AG of a data security incident involving a third-party software vulnerability on its website. Unauthorized acquisition of credit card information for purchases made between June 14 and July 12, 2024, was identified. 46 NH residents were affected. Notifications were mailed in August 2024.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_851183810730c470Maine State AGfiled 2024-08-23Verified
- bd_e3f9657b8d248324Montana State AGfiled 2024-08-23Verified
- bd_151b6ab94dc3a35fCalifornia State AGfiled 2024-08-22(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/spau-holdings-artifact-uprising-20240823.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2024
- Raw hash
- fd9154f80500cdce00d1a2b19fd8365b3504b42e67cc874eace46985d2f0b293
Reporting entity
- Name
- Artifact Uprisingnorm: artifact uprising
Victim entity
- Name
- Artifact Uprisingnorm: artifact uprising
Incident
- Discovered
- Jul 12, 2024
- Materiality determined
- Jul 26, 2024
- Notification sent
- Aug 22, 2024
- Affected individuals
- 46
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.