HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
BSN Sports, Inc.
bd_8325df44050a08b7 · schema v1 · pii pii-v1
Full breach record for BSN Sports, Inc. →BSN Sports, LLC disclosed that a criminal actor compromised the security of checkout pages on four eCommerce websites between April 24, 2019, and January 5, 2021. The attacker copied payment card account numbers, expiration dates, verification numbers, names, addresses, and contact information. BSN secured the websites, implemented technical safeguards, and offered one year of dark web monitoring to affected customers.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538406
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 26, 2021
- Raw hash
- 99c737478663e7c79d7f1565eca9bda5510c9a6569d72c361f12f96a0f0b595c
Reporting entity
- Name
- BSN Sports, Inc.norm: bsn sports
Victim entity
- Name
- BSN Sports, Inc.norm: bsn sports
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.