HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
Quality CPR Care LLC
bd_877385644bfbf0b5 · schema v1 · pii pii-v1
Full breach record for Quality CPR Care LLC →Quality CPR Care LLC (dba American CPR Care Association) disclosed a data breach in California involving unauthorized access to its payment card environment via a webshell. The incident, discovered on November 29, 2020, potentially exposed customer names and debit/credit card numbers stored temporarily for quality assurance. The company engaged forensic investigators, reset passwords, and enhanced policies to stop storing payment card data.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_233144518da5e8e4Maine State AGfiled 2021-03-15Candidate
- bd_7ff0e95a00b22f79Oregon State AGfiled 2021-03-15Verified
- bd_d9c9762db05b94a3Montana State AGfiled 2021-03-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539140
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 15, 2021
- Raw hash
- 5ade8e49c9b9dedaee29aa9a7ee06a691948fefdb700dbef84c18c3cb08db9f8
Reporting entity
- Name
- Quality CPR Care LLCnorm: quality cpr care
Victim entity
- Name
- Quality CPR Care LLCnorm: quality cpr care
Incident
- Discovered
- Nov 29, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.