HackingSkimmerCapture Stored DataCustomer Data InvolvedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Totally Reliable
bd_8ddbfbb06d2cdce5 · schema v1 · pii pii-v1
Full breach record for Totally Reliable →Totally Promotional disclosed that an unauthorized actor placed code on its website's payment platform to capture customer payment card information. The incident occurred in multiple windows between November 20, 2023, and October 20, 2024. Suspicious activity was identified on July 10, 2024. The company removed the malicious code and reviewed policies. Affected data includes names and payment card information.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0863f54abe165fa0New Hampshire State AGfiled 2024-10-16(40d gap)Verified
- bd_1c60e5c2cd51bcd7California State AGfiled 2024-10-16(40d gap)Verified
- bd_2fda4f5e88961d5aVermont State AGfiled 2024-10-16(40d gap)Verified
- bd_7ee71c6bd4ebf587Oregon State AGfiled 2024-10-16(40d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 40d gap
- bd_815acf1458eb700cMontana State AGfiled 2024-10-16(40d gap)Verified by operator
- bd_8eead9e4b3730fb0Indiana State AGfiled 2024-10-16(40d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-595375
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 25, 2024
- Raw hash
- 3927166d1ed071ac6d0b83b967b9b29ee041bd2efdf8b1a7d405ce664ff4c576
Reporting entity
- Name
- Totally Reliablenorm: totally reliable
- Domain
- totallyreliable.com
Victim entity
- Name
- Totally Reliablenorm: totally reliable
- Domain
- totallyreliable.com
Incident
- Discovered
- Jul 10, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1185 Browser Session HijackingT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notifying individuals and relevant regulators as required
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(138 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.