HackingVulnerability ExploitCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Lazarus Naturals
bd_58787bdfef18d54e · schema v1 · pii pii-v1
Full breach record for Lazarus Naturals →Etz Hayim Holdings, S.P.C. d/b/a Lazarus Naturals disclosed a cyberattack where malicious actors exploited a software vulnerability on its website to insert malicious code. The incident occurred between March 1 and June 2, 2023, and was discovered on July 10, 2023. Affected data includes names, billing addresses, and credit/debit card information (card number, expiration date, security code). The company engaged forensic experts, notified the FBI, and is offering 24 months of credit monitoring.
California clockDiscovered Jul 10, 2023 → Notified Aug 3, 202324d ✓ CA 60-day OK23 days discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_7ad62830ad6eb6b0Maine State AGfiled 2023-08-02Verified
- bd_0aff90e77efd0458Oregon State AGfiled 2023-08-07(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571232
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 2, 2023
- Raw hash
- ad9241df029b29d5de3d55621cbbcc8868a6fc394d47cc13a7292594f3ab2255
Reporting entity
- Name
- Lazarus Naturalsnorm: lazarus naturals
- Domain
- lazarusnaturals.com
Victim entity
- Name
- Lazarus Naturalsnorm: lazarus naturals
- Domain
- lazarusnaturals.com
Incident
- Discovered
- Jul 10, 2023
- Materiality determined
- —
- Notification sent
- Aug 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported the Incident to the Federal Bureau of Investigation (“FBI”)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 24d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 10, 2023→ Notified: Aug 3, 202324d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.