HackingVulnerability ExploitData ExfiltratedTargetedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
GRAETER'S ICE CREAM COMPANY
bd_3e95023e51d508eb · schema v1 · pii pii-v1
Full breach record for GRAETER'S ICE CREAM COMPANY →Graeter’s Ice Cream Company notified California AG of a data breach involving unauthorized code on its website checkout page. The code, present from June 28 to December 17, 2018, copied customer payment card details, names, and addresses. The company engaged a cybersecurity firm and implemented password resets and code scans.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_91b64b80c558b1d3Montana State AGfiled 2019-01-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-143911
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 15, 2019
- Raw hash
- cd7d00bdea1eaa47ed0763e816f17f8a17f6e570adaf5bd511b50857d0184d48
Reporting entity
- Name
- GRAETER'S ICE CREAM COMPANYnorm: graeter s ice cream
- Domain
- graeters.com
Victim entity
- Name
- GRAETER'S ICE CREAM COMPANYnorm: graeter s ice cream
- Domain
- graeters.com
Incident
- Discovered
- Dec 17, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.