HackingRetail & ConsumerRetailSkimmerCapture App DataCustomer Data InvolvedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowResolved
BarristerBooks, Inc.
bd_31eae45a49576771 · schema v1 · pii pii-v1
Full breach record for BarristerBooks, Inc. →BarristerBooks, Inc., a family-owned online law book retailer, discovered that an unknown party obtained payment card information from customers who made purchases on barristerbooks.com, lawbooks.com, or lawbooksforless.com between July 7, 2020 and September 11, 2020. Exposed data included cardholder names, account numbers, expiration dates, and CVVs. The company engaged forensic investigators, notified the FBI, and migrated payment processing to PayPal.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_bc43318e83e33d62Maine State AGfiled 2020-11-11Candidate
- bd_cf8853861fdd9a5cMontana State AGfiled 2020-11-11Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-196050
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 11, 2020
- Raw hash
- 66612c0e3c52e658b25b39cd69de2a882bdddb976f21acdb471c1c35e6961715
Reporting entity
- Name
- BarristerBooks, Inc.norm: barristerbooks
- Domain
- barristerbooks.com
Victim entity
- Name
- BarristerBooks, Inc.norm: barristerbooks
- Domain
- barristerbooks.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Nov 10, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1056 Input CaptureT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI) regarding the incident
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.