HackingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Walsworth Yearbooks
bd_67bb34e34f3e7cad · schema v1 · pii pii-v1
Full breach record for Walsworth Yearbooks →Walsworth Publishing Company notified Vermont AG on 2024-11-22 of a data security incident discovered on 2024-02-09 involving its website. The incident potentially exposed names, payment card numbers, expiration dates, and CVVs. Walsworth engaged cybersecurity experts, secured the site, and offered 12 months of credit monitoring. No specific affected count was provided.
Vermont clock✗ VT AG >45 bday41 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3287fdfe451ecf10Washington State AGfiled 2024-11-22Candidate
- bd_69ad9c043ff80bb0Oregon State AGfiled 2024-11-22Verified by operator
- bd_a45fbbd74447be23Indiana State AGfiled 2024-11-22Verified
- bd_ac3c3b99ea518e91New Hampshire State AGfiled 2024-11-22Verified
Show 2 more filings ↓Show fewer ↑
- bd_f9c492d660ecbd62Montana State AGfiled 2024-11-22Candidate
- bd_fc97bff18fca0120California State AGfiled 2024-11-22Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-11-22-walsworth-publishing-company-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2024
- Raw hash
- e40509970e6ee696e039c958c643fc68a9e91094a6e2d652983e489a06d3758f
Reporting entity
- Name
- Walsworth Yearbooksnorm: walsworth yearbooks
- Domain
- walsworthyearbooks.com
Victim entity
- Name
- Walsworth Yearbooksnorm: walsworth yearbooks
- Domain
- walsworthyearbooks.com
Incident
- Discovered
- Feb 9, 2024
- Materiality determined
- Nov 1, 2024
- Notification sent
- Nov 22, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 41 weeks(287 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.