HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowActive
CORE Cashless
bd_5ad9260689983a28 · schema v1 · pii pii-v1
Full breach record for CORE Cashless →CORE Cashless, LLC issued a supplemental notice to Delaware residents regarding a data security incident. An unauthorized individual accessed the company's environment between January 29, 2022, and July 30, 2022, potentially exposing payment card information and names/addresses of individuals who processed payments at impacted merchants. CORE engaged cybersecurity counsel and provided 12 months of identity monitoring services via Kroll.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0ff92766873c89bcMontana State AGfiled 2023-01-12(41d gap)Verified by operator
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/02/Supplemental-Notice-CORE-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 2, 2022
- Raw hash
- d742fcd9dc2dbb14db041c06e73905997027b8581589baf5ccf3a0d932afc759
Reporting entity
- Name
- CORE Cashlessnorm: core cashless
Victim entity
- Name
- CORE Cashlessnorm: core cashless
Incident
- Discovered
- Jul 28, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.