MalwareRansomwareData EncryptedTargetedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Manduka
bd_7ff02f57c5673209 · schema v1 · pii pii-v1
Full breach record for Manduka →Manduka notified California AG of a data breach involving unauthorized malware installation on its e-commerce platform. The incident occurred between Feb 22, 2017, and Mar 5, 2018, potentially compromising payment card info (names, card numbers, expiration dates, security codes) of customers. Manduka engaged forensic investigators, reported to the FBI and Secret Service, and notified payment card brands.
California clockDiscovered Feb 25, 2018 → Notified Mar 18, 201821d ✓ CA 60-day OK4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_459f89eec1979764Washington State AGfiled 2018-03-27Verified
- bd_5ecb4e4d561a06bfOregon State AGfiled 2018-03-27Verified
- bd_900e824b2ddbde8dMontana State AGfiled 2018-03-26(1d gap)Candidate
- bd_197f9054f6cba465California State AGfiled 2018-06-08(73d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134813
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2018
- Raw hash
- b26030a1fe5b17a9d8150a45daceedf54d1160de7cda6f536d39f909897fc72e
Reporting entity
- Name
- Mandukanorm: manduka
Victim entity
- Name
- Mandukanorm: manduka
Incident
- Discovered
- Feb 25, 2018
- Materiality determined
- —
- Notification sent
- Mar 18, 2018
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to the Federal Bureau of Investigation (“FBI”)working with both the FBI and the United States Secret Service
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 25, 2018→ Notified: Mar 18, 201821d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.