HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
The National Wildlife Federation
bd_616fbe76043ab38a · schema v1 · pii pii-v1
Full breach record for The National Wildlife Federation →The National Wildlife Federation disclosed a data security incident involving its Zoobooks.com payment card processing. Malicious code captured customer payment information (names, addresses, card numbers, CVVs) between Feb 6, 2019, and Dec 10, 2020. NWF retained forensic specialists, remediated the issue, and notified affected individuals, including 319 Rhode Island residents.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_53218a1414a3fef4Washington State AGfiled 2021-03-24Candidate
- bd_b39ba2952a25d8d0Maine State AGfiled 2021-03-24Verified
- bd_ddb6c4675f8bd76cOregon State AGfiled 2021-03-24Verified
- bd_e850d4465859eee1South Carolina State AGfiled 2021-03-24Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539446
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 24, 2021
- Raw hash
- 1120214f3c645ba4d3b3a7c8508c1bad4bf6c4fecdaab612c6ce0c61e1cfee31
Reporting entity
- Name
- The National Wildlife Federationnorm: the national wildlife federation
Victim entity
- Name
- The National Wildlife Federationnorm: the national wildlife federation
Incident
- Discovered
- Dec 4, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(110 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.