HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedData EncryptedRansom DemandedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
WILTON BRANDS LLC
bd_399085c1fc2a54d9 · schema v1 · pii pii-v1
Full breach record for WILTON BRANDS LLC →Wilton Brands LLC notified California AG that a malicious user modified its shopping cart functionality between Oct 8, 2012 and Jan 8, 2013, intercepting customer PII and payment card data (including CVV). At least one fraudulent transaction occurred. Wilton notified law enforcement, replaced its webserver, shifted payment processing to a third party, and offered one year of Experian ProtectMyID monitoring.
California clockDiscovered Jan 8, 2013 → Notified Jan 25, 201317d ✓ CA 60-day OK16 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_eef2e597d73594d0California State AGfiled 2012-12-12(43d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-38734
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 24, 2013
- Raw hash
- 0b21b4a403c59b01614f218514eb02afd49943f13dc8e27a447208ff0ce83231
Reporting entity
- Name
- WILTON BRANDS LLCnorm: wilton brands
- Domain
- wilton.com
Victim entity
- Name
- WILTON BRANDS LLCnorm: wilton brands
- Domain
- wilton.com
Incident
- Discovered
- Jan 8, 2013
- Materiality determined
- —
- Notification sent
- Jan 25, 2013
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 17d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 8, 2013→ Notified: Jan 25, 201317d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.