HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedCREDENTIALSFINANCIAL_CREDENTIALSIDENTITY_BASICLowResolved
Costco Photo Center
bd_9002831beac56b71 · schema v1 · pii pii-v1
Full breach record for Costco Photo Center →Costco Photo Center disclosed a security compromise of its hosting provider's system between June 19, 2014, and July 15, 2015. An unauthorized party deployed malware and potentially accessed email addresses, passwords, credit card security codes, and shipping addresses entered by members. Stored credit card numbers and photos were not believed to be at risk. The site was taken offline, rebuilt with enhanced security, and users were required to reset passwords. Credit monitoring was offered.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ea849776f0d2c965Hawaii State AGfiled 2015-09-29(6d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-57944
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 23, 2015
- Raw hash
- b21ac8c06f7ef20bf00238e1b95f646076cb35d66a8a44352671f1bf4179167f
Reporting entity
- Name
- Costco Photo Centernorm: costco photo center
Victim entity
- Name
- Costco Photo Centernorm: costco photo center
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 17, 2015
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1566 Phishing
- Threat actor
- External
- Third party
- via Host company
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.