HackingStolen CredentialsTargetedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
THE MASSACHUSETTS MEDICAL SOCIETY
bd_6afeeac98ff20369 · schema v1 · pii pii-v1
Full breach record for THE MASSACHUSETTS MEDICAL SOCIETY →Massachusetts Medical Society notified consumers of a data breach involving unauthorized code installed on its e-commerce checkout page (nejm.org) between October 3 and 11, 2024. The code captured payment card details, names, addresses, and emails. The Society removed the code and enhanced safeguards. No specific count of affected individuals was provided in the filing.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_7887a2f3ee5587b4Indiana State AGfiled 2024-12-26Verified
- bd_c0cc85ac9e9879d6New Hampshire State AGfiled 2024-12-26Verified
- bd_c2958815b180d788Maine State AGfiled 2024-12-26Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-12-26-massachusetts-medical-society-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 26, 2024
- Raw hash
- f57c422bd151a240987843a0666add2910720475fc25e09334c093d4864b428d
Reporting entity
- Name
- THE MASSACHUSETTS MEDICAL SOCIETYnorm: the massachusetts medical society
- Domain
- nejm.org
Victim entity
- Name
- THE MASSACHUSETTS MEDICAL SOCIETYnorm: the massachusetts medical society
- Domain
- nejm.org
Incident
- Discovered
- Oct 11, 2024
- Materiality determined
- —
- Notification sent
- Dec 26, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.