HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
JAM Paper & Envelope
bd_8ff32980147e5691 · schema v1 · pii pii-v1
Full breach record for JAM Paper & Envelope →JAM Paper & Envelope notified California customers of a data breach affecting payment card information. The incident occurred between June 15, 2016, and November 6, 2017, involving unauthorized access to payment card data (numbers, expiration, CVV) via their website. The company engaged forensic experts and law enforcement, and is strengthening website security.
California clockDiscovered Nov 17, 2017 → Notified Dec 1, 201714d ✓ CA 60-day OK14 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_aa13d69516c3cedeOregon State AGfiled 2017-12-01Candidate
- bd_b3ed81e4d0fc8bc6Washington State AGfiled 2017-12-01Verified
- bd_bcf72073a4513af2Montana State AGfiled 2017-12-01Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-119442
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 1, 2017
- Raw hash
- 540b23c115e0b8470e3c96996642b409ae6393c0239c2a36c5d40d2449c4b87c
Reporting entity
- Name
- JAM Paper & Envelopenorm: jam paper envelope
- Domain
- jampaper.com
Victim entity
- Name
- JAM Paper & Envelopenorm: jam paper envelope
- Domain
- jampaper.com
Incident
- Discovered
- Nov 17, 2017
- Materiality determined
- —
- Notification sent
- Dec 1, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 14d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 17, 2017→ Notified: Dec 1, 201714d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.