HackingVulnerability ExploitTargetedPCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
American Society for Clinical Pathology
bd_50dbb9c8e5101fcf · schema v1 · pii pii-v1
Full breach record for American Society for Clinical Pathology →American Society for Clinical Pathology (ASCP) notified California of a cybersecurity attack on its e-commerce website (ascp.org) between March 30 and November 6, 2020. The attack potentially exposed payment card data (card numbers, expiration dates, CVVs) for customers who made purchases during that period. ASCP engaged forensic investigators, resolved the vulnerability, and implemented additional security safeguards. No evidence of misuse was found, and no specific count of affected individuals was disclosed.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539769
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 7, 2021
- Raw hash
- 4fa1af7602a16736df95852d1ade7e5e0bf4c609f8f9348778666b0f4d575305
Reporting entity
- Name
- American Society for Clinical Pathologynorm: american society for clinical pathology
- Domain
- ascp.org
Victim entity
- Name
- American Society for Clinical Pathologynorm: american society for clinical pathology
- Domain
- ascp.org
Incident
- Discovered
- Nov 6, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 weeks(152 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.