HackingRetail & ConsumerRetailVulnerability ExploitCapture App DataData ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCILowActive
Freedom Smokes, Inc.
bd_8d29c1b853ecb2ef · schema v1 · pii pii-v1
Full breach record for Freedom Smokes, Inc. →Freedom Smokes, Inc. (myfreedomsmokes.com) discovered that between approximately March 7 and April 25, 2017, an unauthorized individual accessed portions of their e-commerce website and inserted malicious code designed to capture payment card information (name, address, email, phone, card number, expiration date, CVV) entered during purchases. No SSNs were affected. The company engaged a cybersecurity forensics firm and notified affected customers.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5f022dd30574eeffOregon State AGfiled 2017-06-07(2d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-72375
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 5, 2017
- Raw hash
- 7bc589d588433bdaf35270dbeff2dc66a0889bb0457696feaf69c7e0e10e3d0b
Reporting entity
- Name
- Freedom Smokes, Inc.norm: freedom smokes
Victim entity
- Name
- Freedom Smokes, Inc.norm: freedom smokes
- Domain
- myfreedomsmokes.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 5, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input CaptureT1074 Data Staged
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.