HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICMediumActive
Travel Caddy, Inc.
bd_883eb11ac3b53500 · schema v1 · pii pii-v1
Full breach record for Travel Caddy, Inc. →Travel Caddy, Inc. (dba Travelon) notified the NH Attorney General of a data breach occurring between Nov 13, 2015 and Jun 10, 2016. Malicious code on the website's server collected customer PII (names, addresses, emails) and financial data (credit card numbers, CVV2, expiration dates). The breach was discovered on July 7, 2016, when a third-party web developer alerted the company. Approximately 1,673 individuals nationwide were potentially affected, including 16 New Hampshire residents. The malicious code was deactivated, and customer notifications were sent.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_28dec55f16d5ac4fMontana State AGfiled 2016-08-04Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/travel-caddy-20160804.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 4, 2016
- Raw hash
- 7d3766bd586893f9fb84f2f410d8d6b3d891ed46a4afac97f4eb81b2b390d4c8
Reporting entity
- Name
- FVLDnorm: fvld
Victim entity
- Name
- Travel Caddy, Inc.norm: travel caddy
Incident
- Discovered
- Jul 7, 2016
- Materiality determined
- —
- Notification sent
- Aug 4, 2016
- Affected individuals
- 1,673
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.