HackingVulnerability ExploitCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Shumsky Promotional Agency
bd_75bcd326f8215d4c · schema v1 · pii pii-v1
Full breach record for Shumsky Promotional Agency →Shumsky Promotional Agency notified customers that an unauthorized third party accessed its e-commerce platform provider's system on May 14, 2013, compromising nearly 1,400 cardholder records. Affected data included names, addresses, emails, credit/debit card numbers, expiration dates, and CVV codes. The vulnerability was patched on May 15, 2013. Shumsky engaged security and legal advisors and implemented updated security measures.
California clockDiscovered May 16, 2013 → Notified May 16, 20130d ✓ CA 60-day OK13 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,400 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-41885
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2013
- Raw hash
- da6a9d41892ba0f48af57621124c1a860f831545d52a7ad168c104095d5e730b
Reporting entity
- Name
- Shumsky Promotional Agencynorm: shumsky promotional agency
- Domain
- shumsky.com
Victim entity
- Name
- Shumsky Promotional Agencynorm: shumsky promotional agency
- Domain
- shumsky.com
Incident
- Discovered
- May 16, 2013
- Materiality determined
- —
- Notification sent
- May 16, 2013
- Affected individuals
- 1,400
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via e-commerce platform provider
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 days(13 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 16, 2013→ Notified: May 16, 20130d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.