HackingData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumContained
CP Franchising, LLC
bd_55182f145b4ac83d · schema v1 · pii pii-v1
Full breach record for CP Franchising, LLC →CP Franchising, LLC reported a cybersecurity incident where an unauthorized person gained access to servers on January 30, 2015, via malicious code. Data at risk included names, addresses, credit card numbers, SSNs, and bank account numbers for clients and franchisees. The company engaged the FBI, terminated access, and offered one year of credit monitoring via Experian.
California clockDiscovered Feb 2, 2015 → Notified Feb 20, 201518d ✓ CA 60-day OK23 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e92e9b735c93d50eSouth Carolina State AGfiled 2015-03-04(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-48518
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 25, 2015
- Raw hash
- 43c3a26211ff903d939d21127d75f4569832bf90f49b3ad2d181fd5a85d83e7b
Reporting entity
- Name
- CP Franchising, LLCnorm: cp franchising
Victim entity
- Name
- CP Franchising, LLCnorm: cp franchising
Incident
- Discovered
- Feb 2, 2015
- Materiality determined
- Feb 20, 2015
- Notification sent
- Feb 20, 2015
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Communicated with the FBINotifying state attorneys general and other regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 18d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 2, 2015→ Notified: Feb 20, 201518d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.