HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Superior Labels
bd_7a73c45a629de98d · schema v1 · pii pii-v1
Full breach record for Superior Labels →Superior Labels, Inc. disclosed a data breach affecting approximately 7,000 customers. Hackers exploited a vulnerability in WordPress blogging software to access the order management system between November 3, 2015, and December 11, 2015. Potentially compromised data included customer names, addresses, and credit card numbers. The company removed the vulnerable software, enhanced security measures, engaged forensic investigators, and provided 12 months of identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,000 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-60210
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 25, 2016
- Raw hash
- c35893ed24237263030eca2995812f2ee2cba6fb45a43c7ee5732cd10925a3a3
Reporting entity
- Name
- Superior Labelsnorm: superior labels
- Domain
- superiorlabels.shop
Victim entity
- Name
- Superior Labelsnorm: superior labels
- Domain
- superiorlabels.shop
Incident
- Discovered
- Dec 11, 2015
- Materiality determined
- Feb 19, 2016
- Notification sent
- —
- Affected individuals
- 7,000
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.