HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
HAMILTON BEACH BRANDS, INC.
bd_8c0d902d147260e0 · schema v1 · pii pii-v1
Full breach record for HAMILTON BEACH BRANDS, INC. →Hamilton Beach Brands, Inc. disclosed a security incident involving unauthorized code on its ecommerce website (www.hamiltonbeach.com). The code, present between December 18, 2020, and February 4, 2021, could capture customer payment card information and contact details during checkout. Hamilton Beach engaged a cybersecurity firm, notified law enforcement, and informed payment card networks. No specific count of affected individuals was provided in the notification.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_144ab3124979fa1cMontana State AGfiled 2021-04-09Candidate
- bd_2e182e5b1fc87f02Maine State AGfiled 2021-04-09Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539860
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 9, 2021
- Raw hash
- aaaa26597966c633cf097454a932eed6fb8d243b0122014f93e20c40c4974cc6
Reporting entity
- Name
- HAMILTON BEACH BRANDS, INC.norm: hamilton beach brands
Victim entity
- Name
- HAMILTON BEACH BRANDS, INC.norm: hamilton beach brands
Incident
- Discovered
- Feb 4, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement and is cooperating with their investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.