HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
Blue Spring Partners
bd_4250242027456b1d · schema v1 · pii pii-v1
Full breach record for Blue Spring Partners →Blue Spring Partners, LLC (dba Fin Fun) reported a data breach affecting customers who made payments on finfunmermaid.com between April 25 and May 14, 2015. Malware was installed on the server checkout page, compromising payment card data, names, addresses, emails, and encrypted passwords. The company engaged Kroll for identity theft protection and notified the FBI.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-56084
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 21, 2015
- Raw hash
- 757bbc4609aa35913914c435c4fc319e26699f246033af4ab372850e957df6e6
Reporting entity
- Name
- Blue Spring Partnersnorm: blue spring
- Domain
- bluespringpartners.com
Victim entity
- Name
- Blue Spring Partnersnorm: blue spring
- Domain
- bluespringpartners.com
Incident
- Discovered
- Apr 30, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.