HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
Running Warehouse LLC
bd_8b2b4b6011e01e85 · schema v1 · pii pii-v1
Full breach record for Running Warehouse LLC →Running Warehouse LLC notified Delaware AG of a data security incident occurring October 1, 2021, discovered October 15, 2021. Unauthorized access resulted in the theft of payment card information (names, addresses, card numbers, CVV). The company engaged forensic investigators, reported to payment brands and law enforcement, and enhanced site security. Notification letters were sent December 16, 2021.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_29205aaea2d80515Oregon State AGfiled 2021-12-16Candidate
- bd_50a41abd0cab62baHawaii State AGfiled 2021-12-16Verified
- bd_5cd9bbff700e0379Montana State AGfiled 2021-12-16Verified
- bd_e66c1d9e5004ca11South Carolina State AGfiled 2021-12-16Verified
Show 4 more filings ↓Show fewer ↑up to 117d gap
- bd_ed278a6c9f0d6163Maine State AGfiled 2021-12-16Verified
- bd_6bf8934f0ec90678Washington State AGfiled 2021-12-17(1d gap)Verified
- bd_d324255dd74503baCalifornia State AGfiled 2021-12-18(2d gap)Verified
- bd_4189f65f175d57c6California State AGfiled 2022-04-12(117d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/12/Pages-from-Running-Warehouse-Regulatory-Notice-Packet-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2021
- Raw hash
- 4e4281dbbeea96f65866039c6c998b59b7cb5b32808d2e31f5fbc92004039a47
Reporting entity
- Name
- Running Warehouse LLCnorm: running warehouse
Victim entity
- Name
- Running Warehouse LLCnorm: running warehouse
Incident
- Discovered
- Oct 15, 2021
- Materiality determined
- —
- Notification sent
- Dec 16, 2021
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.