HackingStolen CredentialsCapture Stored DataCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Svanaco, Inc.
bd_7867b4beefec01a7 · schema v1 · pii pii-v1
Full breach record for Svanaco, Inc. →Svanaco, Inc. (dba Americaneagle.com) disclosed that an unauthorized actor used compromised employee credentials to install malicious code on the Nueske's e-commerce platform hosted by Americaneagle.com. The malware captured payment card information (names, card numbers, expiration dates, security codes) for transactions processed between July 25, 2022, and December 9, 2022. The incident was detected on November 16, 2022. The company engaged forensic investigators, secured the store, and notified payment card brands and law enforcement.
California clockDiscovered Nov 16, 2022 → Notified Mar 29, 2023133d ✗ CA 60-day late19 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_6982d17fbe534836Vermont State AGfiled 2023-03-29Verified
- bd_6a5e460bdfe3982fIdaho State AGfiled 2023-03-29Candidate
- bd_960bc926598baf2bMontana State AGfiled 2023-03-29Verified
- bd_38647635650a2e39Maine State AGfiled 2023-03-30(1d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 6d gap
- bd_3d4e7b6a5b4e4b31Washington State AGfiled 2023-03-30(1d gap)Verified
- bd_4d546795285d3ae3Oregon State AGfiled 2023-03-30(1d gap)Verified
- bd_dd290f34671b4c59South Carolina State AGfiled 2023-03-30(1d gap)Verified
- bd_7a8982d1bcd32f39Oregon State AGfiled 2023-04-04(6d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564886
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 29, 2023
- Raw hash
- 0746a5c8c6a5e4841ebd9defa71f2fbbb8ffb044a9c2f008f65a65441795bd85
Reporting entity
- Name
- Svanaco, Inc.norm: svanaco
- Domain
- americaneagle.com
Victim entity
- Name
- Svanaco, Inc.norm: svanaco
- Domain
- americaneagle.com
Incident
- Discovered
- Nov 16, 2022
- Materiality determined
- —
- Notification sent
- Mar 29, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1505.003 Web ShellT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to the various payment card brandsReported the incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 19 weeks(133 days from discovery to filing)
- Compliance flags
- CA 60-day late · 133d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 16, 2022→ Notified: Mar 29, 2023133d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.