HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
TOG Hold Co. & Thirty One Gifts
bd_2bd30f5a0456f3fc · schema v1 · pii pii-v1
Full breach record for TOG Hold Co. & Thirty One Gifts →Thirty One Gifts LLC disclosed that an unauthorized third party captured credit card information entered on its website mythirtyone.com. The company learned of the incident on July 21, 2023. Affected data includes credit card numbers, expiration dates, card security codes, names, addresses, and email addresses. The company engaged an incident response team, notified law enforcement and card brands, and stopped the unauthorized access. Two years of identity monitoring are being provided to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0fa949a288a5a852New Hampshire State AGfiled 2023-08-25(1d gap)Verified
- bd_d906819eee79ceb6Oregon State AGfiled 2023-08-29(3d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572457
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 26, 2023
- Raw hash
- 01fe2884d2f722df6e202bc9058be386237506fa5d52fc1cf37b3506d4256da5
Reporting entity
- Name
- TOG Hold Co. & Thirty One Giftsnorm: tog hold co thirty one gifts
- Domain
- mythirtyone.com
Victim entity
- Name
- TOG Hold Co. & Thirty One Giftsnorm: tog hold co thirty one gifts
- Domain
- mythirtyone.com
Incident
- Discovered
- Jul 21, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcementNotified credit card brands
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.