HackingCustomer Data InvolvedPCIFINANCIAL_ACCOUNTMediumContained
Crago, Inc
bd_5b981c443cc8aaf1 · schema v1 · pii pii-v1
Full breach record for Crago, Inc →Crago, Inc. d/b/a PrintingCenterUSA reported a data security incident where an unauthorized third party captured credit card information from its website between September 27, 2023, and November 23, 2023. The company discovered the incident on January 5, 2024. A total of 3,159 individuals were affected, including 24 New Hampshire residents. The company engaged its incident response team, notified law enforcement and credit card brands, and provided free credit monitoring services to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_aa19d615c18c0608Indiana State AGfiled 2024-01-31(1d gap)Verified
- bd_b9ecc7177e10b9e5Maine State AGfiled 2024-01-31(1d gap)Candidate
- bd_f2f868d305ec57e0Montana State AGfiled 2024-02-01(2d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/crago-dba-printingcenterusa-20240130.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2024
- Raw hash
- a45083238af5384d736330b4b58b82c37fce406af305e7fc40724f893bbb9136
Reporting entity
- Name
- Crago, Incnorm: crago
Victim entity
- Name
- Crago, Incnorm: crago
Incident
- Discovered
- Jan 5, 2024
- Materiality determined
- —
- Notification sent
- Jan 31, 2024
- Affected individuals
- 3,159
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.