HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTHighContained
Creative Services, Inc.
bd_361b96baa57efa2b · schema v1 · pii pii-v1
Full breach record for Creative Services, Inc. →Creative Services, Inc. reported an external system breach (hacking) occurring on November 23, 2021, discovered on January 25, 2022. The incident affected 165,226 individuals, including 2,062 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). The company provided written notification and offered 12 months of credit monitoring and identity theft restoration services through Equifax.
Maine clockDiscovered Jan 25, 2022 → Filed with AG Apr 18, 202283d ⏱ ME AG >30d12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_3c3b61d1f85192c6California State AGfiled 2022-04-18Verified
- bd_57dcbca496f5c717New Hampshire State AGfiled 2022-04-22(4d gap)Verified
- bd_46b3db9060c7d4b6New Hampshire State AGfiled 2022-02-28(49d gap)Verified
- bd_750ed45764cbfacfSouth Carolina State AGfiled 2022-02-24(53d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 76d gap
- bd_1be64c03d8c522bdMaine State AGfiled 2022-02-23(54d gap)Verified
- bd_737a9c0214d5b59eMontana State AGfiled 2022-02-23(54d gap)Verified
- bd_fa6006624ab4fa0cCalifornia State AGfiled 2022-02-23(54d gap)Verified
- bd_512e294023a08ef7New Hampshire State AGfiled 2022-02-07(70d gap)Verified
- bd_5b7645ca55904b9fMaine State AGfiled 2022-02-01(76d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/00130b43-1fca-4db5-85a9-a79191d6cb26.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 18, 2022
- Raw hash
- c7913e80f4c7f274cfb91a45ea645c22e861b93267aea65e53b0cf8b14a99b6f
Reporting entity
- Name
- Creative Services, Inc.norm: creative services
- Domain
- creativeservices.com
Victim entity
- Name
- Creative Services, Inc.norm: creative services
- Domain
- creativeservices.com
Incident
- Discovered
- Jan 25, 2022
- Materiality determined
- —
- Notification sent
- Feb 23, 2022
- Affected individuals
- 165,226
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with the Maine Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- ME AG >30d · 83d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 25, 2022→ Filed with AG: Apr 18, 202283d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.