HackingVulnerability ExploitSupply Chain (3P Vendor)N-DayData ExfiltratedCustomer Data InvolvedPIIIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Advantage Gold
bd_6e5ed94e189888b5 · schema v1 · pii pii-v1
Full breach record for Advantage Gold →Advantage Gold notified the California AG of a data breach in which threat actors exploited a vulnerability in third-party firewall software to gain unauthorized access to its networks. The incident occurred in late Q3/early Q4 2025. Affected data includes names, addresses, contact information, limited SSNs, and limited custodian account numbers. Advantage Gold engaged outside cybersecurity experts and is offering 24 months of complimentary Experian IdentityWorks to affected individuals.
California clockConsumers notified Mar 27, 2026 → AG copy submitted Mar 27, 20260d ✓ CA AG copy ≤15d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_b4195eb2e9c942e9Indiana State AGfiled 2026-03-27Verified
- bd_169b81ebe56ee428Maine State AGfiled 2026-03-29(2d gap)Candidate
- bd_3b1861f37409e091Vermont State AGfiled 2026-03-29(2d gap)Verified
- bd_cde4ae1eb8212278Texas State AGfiled 2026-03-30(3d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 3d gap
- bd_e831c4d2bbadd0faNew Hampshire State AGfiled 2026-03-30(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621025
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2026
- Raw hash
- de1f88a4969a274d1a12701f0c0bd1f02810490a8efb218b91d3abe6646c14fa
Reporting entity
- Name
- Advantage Goldnorm: advantage gold
- Domain
- advantagegold.com
Victim entity
- Name
- Advantage Goldnorm: advantage gold
- Domain
- advantagegold.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Mar 27, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified California Attorney General
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- CA AG copy ≤15d · 0d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status California Consumers notified: Mar 27, 2026→ AG copy submitted: Mar 27, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.