HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Oregon Zoo
bd_8f16876c653d58c0 · schema v1 · pii pii-v1
Full breach record for Oregon Zoo →Oregon Zoo notified customers of a data breach involving payment card information. On June 26, 2024, the zoo detected suspicious activity in its online ticketing service. An investigation revealed that an unauthorized actor redirected transactions from a third-party payment vendor, potentially accessing payment card data from December 20, 2023, to June 26, 2024. Affected data includes names, payment card numbers, CVVs, and expiration dates. The zoo decommissioned the site, notified law enforcement, and is offering 12 months of credit monitoring.
California clockDiscovered Jun 26, 2024 → Notified Aug 16, 202451d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_35707d21e6359ec8New Hampshire State AGfiled 2024-08-16Verified
- bd_7933cf448981fd2eIndiana State AGfiled 2024-08-16Verified
- bd_98ba3ed1bf370bc4Maine State AGfiled 2024-08-16Candidate
- bd_9ce4d77c9ac25ea2Oregon State AGfiled 2024-08-16Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_9fa00df1a160f3cfMontana State AGfiled 2024-08-16Verified
- bd_b908bf9c55af795bWashington State AGfiled 2024-08-16Verified
- bd_030340fa9bf49d29Vermont State AGfiled 2024-08-15(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-590306
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 16, 2024
- Raw hash
- 3b83b137bc69497a6cd3236288a83598a1bd0638fc63d1568f7222e9a9853953
Reporting entity
- Name
- Oregon Zoonorm: oregon zoo
Victim entity
- Name
- Oregon Zoonorm: oregon zoo
Incident
- Discovered
- Jun 26, 2024
- Materiality determined
- —
- Notification sent
- Aug 16, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement
- Third party
- via third-party vendor who processed online ticket purchases
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 51d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 26, 2024→ Notified: Aug 16, 202451d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.