HackingStolen CredentialsTargetedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Totally Reliable
bd_2fda4f5e88961d5a · schema v1 · pii pii-v1
Full breach record for Totally Reliable →Totally Promotional notified consumers of a data breach involving unauthorized code placed on its website payment platform. The incident occurred between November 20, 2023, and July 18, 2024, capturing names and payment card information. The company removed the malicious code and is notifying affected individuals and regulators.
Vermont clock✗ VT AG >45 bday14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0863f54abe165fa0New Hampshire State AGfiled 2024-10-16Verified
- bd_1c60e5c2cd51bcd7California State AGfiled 2024-10-16Verified
- bd_7ee71c6bd4ebf587Oregon State AGfiled 2024-10-16Candidate
- bd_815acf1458eb700cMontana State AGfiled 2024-10-16Verified by operator
Show 2 more filings ↓Show fewer ↑up to 40d gap
- bd_8eead9e4b3730fb0Indiana State AGfiled 2024-10-16Verified
- bd_8ddbfbb06d2cdce5California State AGfiled 2024-11-25(40d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-10-16-totally-promotional-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 16, 2024
- Raw hash
- 37e0f9af24e2c13f36e68716e795c5f136943a2aaa7d530ee208d08bbb8aa261
Reporting entity
- Name
- Totally Reliablenorm: totally reliable
- Domain
- totallyreliable.com
Victim entity
- Name
- Totally Reliablenorm: totally reliable
- Domain
- totallyreliable.com
Incident
- Discovered
- Jul 10, 2024
- Materiality determined
- —
- Notification sent
- Oct 16, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.