MalwareRetail & ConsumerManufacturingRetailCapture App DataInfostealerData ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Canyon Bakehouse
bd_4cda2b20fcb54ca9 · schema v1 · pii pii-v1
Full breach record for Canyon Bakehouse →Canyon Bakehouse LLC notified customers of a data security incident in which unknown third parties gained unauthorized access to computer systems supporting the company's website and installed malware that compromised payment card information. Payment card data entered on the checkout page between March 29, 2017 and January 9, 2019 may have been obtained without authorization. Affected data includes customer names, payment card numbers, expiration dates, and CVV codes.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ba637a74a06b8b2fMontana State AGfiled 2019-04-09Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-146126
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 9, 2019
- Raw hash
- 4a76057547b91740370ce5aa03d5441c7738705732056fbc3a1646e4aea838e9
Reporting entity
- Name
- Canyon Bakehousenorm: canyon bakehouse
Victim entity
- Name
- Canyon Bakehousenorm: canyon bakehouse
- Industry
- Retail & ConsumerllmManufacturingllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input CaptureT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.