HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Black Phoenix Corp
bd_7dd4353854169aae · schema v1 · pii pii-v1
Full breach record for Black Phoenix Corp →Black Phoenix, Inc. disclosed a cybersecurity incident affecting its Black Phoenix Alchemy Lab (BPAL) website between May 1 and May 16, 2018. Malicious code injected into the AuthorizeNet checkout gateway harvested credit card data for approximately 150 transactions. The company reset passwords, neutralized the code, audited security, moved servers, and notified the FBI and local law enforcement. Data potentially exposed includes names, billing addresses, phone numbers, emails, and credit card details.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed150 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136332
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 17, 2018
- Raw hash
- aae54fde459a232cbe0237aa461198b2f7ef5417a798e20341a0384de21d4922
Reporting entity
- Name
- Black Phoenix Alchemy Labnorm: black phoenix alchemy lab
- Domain
- blackphoenixalchemylab.com
Victim entity
- Name
- Black Phoenix Corpnorm: black phoenix
- Domain
- blackphoenixcorp.com
Incident
- Discovered
- May 16, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 150
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBINotified local law enforcement in Los Angeles, CA
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(1 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.