AccidentalMisconfigurationDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Hnilo Naturals LLC
bd_88d1eb8fe91f9f60 · schema v1 · pii pii-v1
Full breach record for Hnilo Naturals LLC →Hnilo Naturals LLC notified California AG that malicious code was present on its website from October 2020 to May 2021. The incident involved customer names, addresses, and payment card information. The company removed the code and is launching a new e-commerce platform with enhanced security.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e73fb91d0d64aad4Maine State AGfiled 2021-06-09Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541722
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 9, 2021
- Raw hash
- c08c73b46aab88dd8f1aed1306dd701bcc40ed353a5320840bed540266986319
Reporting entity
- Name
- Hnilo Naturals LLCnorm: hnilo naturals
Victim entity
- Name
- Hnilo Naturals LLCnorm: hnilo naturals
Incident
- Discovered
- May 5, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.