American Payroll Institute, Inc. (APA); Global Payroll Management Institute, Inc. (GPMI)
bd_303cdd324a08b354 · schema v1 · pii pii-v1
Full breach record for American Payroll Institute, Inc. (APA); Global Payroll Management Institute, Inc. (GPMI) →American Payroll Institute (APA) disclosed a skimming cyberattack on its website discovered July 13, 2020, with activity dating back to May 13, 2020. A vulnerability in APA's content management system allowed a skimmer to be installed on the login and checkout pages. Unauthorized individuals accessed login credentials and payment card information, along with PII including names, addresses, and job details. APA patched the CMS, installed antivirus, increased patch frequency, and mandated password resets. Affected individuals received 12 months of credit monitoring via Equifax.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193589
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 31, 2020
- Raw hash
- d1d5a54c1762c335e8d704387a9b733bf027394a956ea6d02b390b78ff034ba9
Reporting entity
- Name
- American Payroll Institute, Inc.norm: american payroll institute
Victim entity
- Name
- American Payroll Institute, Inc. (APA); Global Payroll Management Institute, Inc. (GPMI)norm: american payroll institute inc apa global payroll management institute inc gpmi
Incident
- Discovered
- Jul 13, 2020
- Materiality determined
- Aug 13, 2020
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIICREDENTIALSFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.