HackingStolen CredentialsPhishingCustomer Data InvolvedTargetedPIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
CertifiKID Holdings, LLC
bd_7c51879041e10b2d · schema v1 · pii pii-v1
Full breach record for CertifiKID Holdings, LLC →CertifiKid LLC reported a data breach where malicious code was inserted into its e-commerce server between Jan 25 and Mar 19, 2016. Discovered Mar 25, 2016, the incident exposed customer PII, credit card data, and credentials. CertifiKid engaged forensic experts, notified card brands, and provided one year of Kroll identity monitoring services.
California clockDiscovered Mar 25, 2016 → Notified Mar 25, 20160d ✓ CA 60-day OK6 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_ba182c438b8bba0fMontana State AGfiled 2016-05-05Candidate
- bd_22dee931a80c352aOregon State AGfiled 2016-05-27(22d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-61677
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 5, 2016
- Raw hash
- d46f71b3634db2c14e247c24eb4a639077585e510e3babeb3fc1e80c49959dd9
Reporting entity
- Name
- CertifiKID Holdings, LLCnorm: certifikid holdings
Victim entity
- Name
- CertifiKID Holdings, LLCnorm: certifikid holdings
Incident
- Discovered
- Mar 25, 2016
- Materiality determined
- —
- Notification sent
- Mar 25, 2016
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input CaptureT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the major card brands affected by this data breach
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 25, 2016→ Notified: Mar 25, 20160d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.