HackingStolen CredentialsCustomer Data InvolvedPCIFINANCIAL_ACCOUNTLowContained
USA Pickleball
bd_4bc7b42d7b481a89 · schema v1 · pii pii-v1
Full breach record for USA Pickleball →Pickleball Central notified the NH AG of a data event affecting 15 NH residents. An unauthorized script on its e-commerce site captured payment card info between March 10-22, 2023. The company detected the incident on March 23, 2023, removed the script, and sent notices to affected individuals and regulators on June 16, 2023.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3184f94800760730Montana State AGfiled 2023-06-16(4d gap)Candidate
- bd_b85c117e1b014185Vermont State AGfiled 2023-06-16(4d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pickleball-central-20230620.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 20, 2023
- Raw hash
- 00c66dffba1792b623c41aedeb43b3505e8abb8b9aab31066bff9cdca3425d5d
Reporting entity
- Name
- USA Pickleballnorm: usa pickleball
- Domain
- usapickleball.org
Victim entity
- Name
- USA Pickleballnorm: usa pickleball
- Domain
- usapickleball.org
Incident
- Discovered
- Mar 23, 2023
- Materiality determined
- —
- Notification sent
- Jun 16, 2023
- Affected individuals
- 15
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(89 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.