HackingSQL InjectionData ExfiltratedCustomer Data InvolvedPIIFINANCIAL_ACCOUNTCREDENTIALSLowContained
MLSGear.com
bd_484016414d72ea4c · schema v1 · pii pii-v1
Full breach record for MLSGear.com →MLSGear.com notified the New Hampshire Attorney General on February 1, 2008, regarding unauthorized access to customer data between January and August 2007. Approximately 169 New Hampshire residents were affected. The breach involved SQL Injection attacks targeting a third-party service provider, exposing names, addresses, credit/debit card info, and passwords. MLSGear terminated the provider, purged passwords, and offered one year of credit monitoring via Kroll.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed169 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mlsgear-20080201.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 1, 2008
- Raw hash
- 0cc920ebede3497bdac9cdd375042a85dc48aa1e849439f6683ce9431b6b888c
Reporting entity
- Name
- MLSGear.comnorm: mlsgearcom
Victim entity
- Name
- MLSGear.comnorm: mlsgearcom
Incident
- Discovered
- Feb 1, 2008
- Materiality determined
- —
- Notification sent
- Feb 1, 2008
- Affected individuals
- 169
- Data types
- PIIFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.