HackingVulnerability ExploitCapture Stored DataCustomer Data InvolvedTargetedPCIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Rev-A-Shelf
bd_815c815df0422775 · schema v1 · pii pii-v1
Full breach record for Rev-A-Shelf →Rev-A-Shelf, LLC, a subsidiary of Jones Plastic & Engineering, disclosed a data security incident where unauthorized code was injected into its website between July 12, 2022, and November 28, 2022. The code attempted to capture customer payment information during checkout. The breach was discovered on November 28, 2022. Notifications were sent to 13 New Hampshire residents whose names, addresses, and credit card details may have been compromised.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed13 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/jones-plastic-engineering-rev-a-shelf-20230127.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 27, 2023
- Raw hash
- 3919fbf8011e1e26a0c068cf9b04a704f65276bb55d1453110beedd0d556610d
Reporting entity
- Name
- Jones Plasticnorm: jones plastic
- Domain
- jonesplastic.com
Victim entity
- Name
- Rev-A-Shelfnorm: rev a shelf
- Domain
- rev-a-shelf.com
Incident
- Discovered
- Nov 28, 2022
- Materiality determined
- Jan 5, 2023
- Notification sent
- Jan 27, 2023
- Affected individuals
- 13
- Data types
- PCIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.