MalwareRansomwareSupply Chain (3P Vendor)Data ExfiltratedData EncryptedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowActive
Aptos Network
bd_3b0817bc12a5f5cb · schema v1 · pii pii-v1
Full breach record for Aptos Network →Mrs Prindables reported a data breach involving its third-party payment processor, Aptos Inc. Unauthorized actors accessed and placed malware on Aptos' platform, affecting 40 online retailers. The breach occurred between February 2016 and December 2016, with discovery in November 2016. Exposed data included names, emails, addresses, phone numbers, and payment card numbers (excluding CVV). Mrs Prindables engaged a cybersecurity firm, updated security controls, and cooperated with federal law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66569
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2017
- Raw hash
- b9ef6c02e5dd59e16c2442a0d843efaef115ffed528cd6817732d003a1459fdd
Reporting entity
- Name
- Mrs Prindablesnorm: mrs prindables
Victim entity
- Name
- Aptos Networknorm: aptos network
- Domain
- aptosnetwork.com
Incident
- Discovered
- Nov 1, 2016
- Materiality determined
- Feb 1, 2016
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 17 weeks(118 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.