MalwareRansomwareData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTLowContained
The Crack Shack
bd_6d728a724c16234d · schema v1 · pii pii-v1
Full breach record for The Crack Shack →The Crack Shack Enterprises, LLC (Encinitas, CA) disclosed a payment card data breach affecting customers between August 19, 2018, and September 23, 2019. Malware installed on a payment processing server compromised magnetic stripe track data (card numbers, expiration dates, CVV). The company engaged forensic investigators and law enforcement, removed the affected server, and reported the incident to major credit card brands.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-186154
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 17, 2020
- Raw hash
- 96f211f9200329aaf2d7cc85f688a0dbc9404f9a9ecad618b6f4f08ecb324357
Reporting entity
- Name
- The Crack Shacknorm: the crack shack
- Domain
- crackshack.com
Victim entity
- Name
- The Crack Shacknorm: the crack shack
- Domain
- crackshack.com
Incident
- Discovered
- Jan 17, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.