HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
BookShark LLC
bd_8c98ed4f58647c28 · schema v1 · pii pii-v1
Full breach record for BookShark LLC →BookShark LLC reported a data breach involving unauthorized code injected into its website (bookshark.com) between March 11, 2019, and August 26, 2019. The code captured customer login credentials and payment card details (including CVV). BookShark engaged a cybersecurity firm, removed the code, reset passwords, and notified affected California residents via statutory breach notices.
California clockDiscovered Aug 26, 2019 → Notified Oct 24, 201959d ✓ CA 60-day OK9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-183846
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 25, 2019
- Raw hash
- 2f5a1eb0afe01c654d1adefc1f87505bc2142df5f950e0d0375961b893f1ffec
Reporting entity
- Name
- BookShark LLCnorm: bookshark
- Domain
- bookshark.com
Victim entity
- Name
- BookShark LLCnorm: bookshark
- Domain
- bookshark.com
Incident
- Discovered
- Aug 26, 2019
- Materiality determined
- —
- Notification sent
- Oct 24, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 59d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 26, 2019→ Notified: Oct 24, 201959d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.