HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Real Estate Business Services, Inc.
bd_37d1d2afed190a7e · schema v1 · pii pii-v1
Full breach record for Real Estate Business Services, Inc. →Real Estate Business Services, Inc. (REBS) disclosed a data breach involving malware on store.car.org payment processing software between March 13, 2017, and May 15, 2017. The malware copied and transmitted customer personal information, including names, addresses, and credit card details (number, expiration, CVC). REBS removed the malware, switched to PayPal, and provided one year of credit monitoring via LifeLock. Law enforcement was notified.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100138
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2017
- Raw hash
- 95d80c811b57e26ca0610c983b81bd4125dfaea96fe337f012257ab99beda874
Reporting entity
- Name
- Real Estate Business Services, Inc.norm: real estate business
Victim entity
- Name
- Real Estate Business Services, Inc.norm: real estate business
Incident
- Discovered
- May 15, 2017
- Materiality determined
- Jul 3, 2017
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.