HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
J&D Brush Co.
bd_44c894ac53dba0fc · schema v1 · pii pii-v1
Full breach record for J&D Brush Co. →J&D Brush Co. LLC (dba Bio Ionic) notified Idaho residents of a cybersecurity incident involving unauthorized code placed on its website. Between March 7 and March 27, 2023, an unauthorized third party potentially captured personal information, including names, addresses, payment card details, and emails, from 54 Idaho residents. The company engaged forensic investigators, notified law enforcement, and is working with credit card brands.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a8bdba0e9d859637Maine State AGfiled 2023-07-17(9d gap)Candidate
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2023/07/7-26-2023-JD-Brush-Co.-LLC.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2023
- Raw hash
- 1e9cfba7bbf5da0f901ab076145bf92d6a21a9bf916602fa75f6f5762ee4357d
Reporting entity
- Name
- J&D Brush Co.norm: j d brush
Victim entity
- Name
- J&D Brush Co.norm: j d brush
Incident
- Discovered
- Mar 7, 2023
- Materiality determined
- —
- Notification sent
- Jul 17, 2023
- Affected individuals
- 54
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(141 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.