HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
TravisMathew
bd_66972d0d36e192eb · schema v1 · pii pii-v1
Full breach record for TravisMathew →TravisMathew, LLC reported a data breach affecting customers who placed orders between August 13, 2018, and September 25, 2018. An unauthorized user modified the website's checkout page to collect customer order details and payment card information, including CVV2 codes. The company engaged a computer security firm and law enforcement, corrected the site modification, and enhanced security measures. Affected customers were notified via letter.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141159
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 25, 2018
- Raw hash
- 29cae9d78138e4f44279198d3c0dc437d16a737eab7d128888d8b6a1d9dbffc1
Reporting entity
- Name
- TravisMathewnorm: travismathew
- Domain
- travismathew.com
Victim entity
- Name
- TravisMathewnorm: travismathew
- Domain
- travismathew.com
Incident
- Discovered
- Sep 24, 2018
- Materiality determined
- —
- Notification sent
- Oct 25, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1074 Data Staged
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.