HackingSQL InjectionData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
The Image Group
bd_749870879e56db2f · schema v1 · pii pii-v1
Full breach record for The Image Group →The Image Group of Toledo, Inc. notified the New Hampshire Attorney General of a security breach affecting 37 state residents. From January to August 2008, hackers exploited an SQL injection vulnerability on the company's e-commerce site to access customer names and credit/debit card information (including CVV). The company shut down the site, conducted a forensic audit, and implemented security measures. Notices were sent to affected individuals on October 6, 2008.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed37 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/image-group-20080929.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 29, 2008
- Raw hash
- df527e27c674d8aef1b125542ca6796779b7deae64dae1057cedd79137ef2c2d
Reporting entity
- Name
- The Image Groupnorm: the image
- Domain
- theimagegroup.espwebsite.com
Victim entity
- Name
- The Image Groupnorm: the image
- Domain
- theimagegroup.espwebsite.com
Incident
- Discovered
- Aug 1, 2008
- Materiality determined
- —
- Notification sent
- Oct 6, 2008
- Affected individuals
- 37
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.