HackingStolen CredentialsTargetedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Hudson Envelope of New Jersey Corp.
bd_8cc6d4e506f992d8 · schema v1 · pii pii-v1
Full breach record for Hudson Envelope of New Jersey Corp. →Hudson Envelope of New Jersey Corp. reported a data breach involving unauthorized code on its e-commerce website between June 25, 2020, and January 11, 2021. The code captured cardholder data, including names, addresses, payment card numbers, and CVVs. Hudson investigated, removed the code, and implemented enhanced logging and security features.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542434
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2021
- Raw hash
- b63f6cc67dee4a85b4c980c434edb4f214824d08146f28b2e76fa3069023dbe5
Reporting entity
- Name
- Hudson Envelope of New Jersey Corp.norm: hudson envelope of new jersey
Victim entity
- Name
- Hudson Envelope of New Jersey Corp.norm: hudson envelope of new jersey
Incident
- Discovered
- Jan 11, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 weeks(170 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.