HackingStolen CredentialsVulnerability ExploitData ExfiltratedTargetedIDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATIONLowContained
Lang Companies, Inc.
bd_62f6361b722f926d · schema v1 · pii pii-v1
Full breach record for Lang Companies, Inc. →The LANG Companies, Inc. notified California AG that unauthorized individuals installed malicious software on a credit card processing server at www.LANG.com between Sept 1 and Oct 19, 2016. Customer data including names, addresses, payment card numbers, expiration dates, and CVVs may have been transmitted outside the system. LANG stopped the incident and is working with card companies.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4b702e4a126e8bf6Montana State AGfiled 2016-11-30Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65124
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 30, 2016
- Raw hash
- 12e67ad7b8410c55854b39a7823286d8093688486e7f27fa629607945780f164
Reporting entity
- Name
- Lang Companies, Inc.norm: lang companies
Victim entity
- Name
- Lang Companies, Inc.norm: lang companies
Incident
- Discovered
- Oct 12, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.