HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
American Association of Critical-Care Nurses
bd_475370cbda26655d · schema v1 · pii pii-v1
Full breach record for American Association of Critical-Care Nurses →American Association of Critical-Care Nurses (AACN) notified customers that an unauthorized party accessed payment card information (card number, expiry, CVV) and personal data (name, address, phone, email) associated with transactions on its website between March 8, 2025, and July 31, 2025. The organization became aware of the issue on July 31, 2025, after investigating with its payment processor and security experts. AACN secured the payment system, implemented security enhancements, and is offering two years of complimentary credit and identity monitoring.
California clockDiscovered Jul 31, 2025 → Notified Aug 29, 202529d ✓ CA 60-day OK29 days discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_6820d7d37f0ea9fdOregon State AGfiled 2025-08-29Verified
- bd_80f7a1e26b0cb573Indiana State AGfiled 2025-08-29Verified
- bd_d266e08df4700389Montana State AGfiled 2025-08-29Verified
- bd_d512ba3bd7ec0b45New Hampshire State AGfiled 2025-08-29Verified
Show 3 more filings ↓Show fewer ↑up to 6d gap
- bd_e05bd527f050d997Maine State AGfiled 2025-08-29Verified
- bd_db08057b57a2ededVermont State AGfiled 2025-09-02(4d gap)Verified
- bd_8242bb219dadeba0Texas State AGfiled 2025-09-04(6d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-607895
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2025
- Raw hash
- 9c2f51e4bef1916118edb3c81675d31ed32788c0ef38a1ab68a65d4ce71554a5
Reporting entity
- Name
- American Association of Critical-Care Nursesnorm: american association of critical care nurses
- Domain
- aacn.org
Victim entity
- Name
- American Association of Critical-Care Nursesnorm: american association of critical care nurses
- Domain
- aacn.org
Incident
- Discovered
- Jul 31, 2025
- Materiality determined
- —
- Notification sent
- Aug 29, 2025
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 31, 2025→ Notified: Aug 29, 202529d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.