HackingSkimmerStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Springfield Armory
bd_903891cd41b25356 · schema v1 · pii pii-v1
Full breach record for Springfield Armory →Springfield Armory experienced a data breach affecting customers who made purchases on its website between October 3, 2015, and October 9, 2016. An unauthorized person gained access to the web server and installed code to copy checkout information, including names, addresses, payment card numbers, and security codes. The incident was discovered in late September 2015 after a payment card network reported unauthorized charges. The company engaged a cybersecurity firm, stopped the incident, and is strengthening website security.
California clockDiscovered Sep 30, 2015 → Notified Nov 16, 2016413d ✗ CA 60-day late14 months discovery → filing
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64988
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2016
- Raw hash
- 3c891c154cb48821e4f3925d5189bace6d15c7365436ebe2418f8e62a5949fc1
Reporting entity
- Name
- Springfield Armorynorm: springfield armory
- Domain
- springfield-armory.com
Victim entity
- Name
- Springfield Armorynorm: springfield armory
- Domain
- springfield-armory.com
Incident
- Discovered
- Sep 30, 2015
- Materiality determined
- —
- Notification sent
- Nov 16, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 months(415 days from discovery to filing)
- Compliance flags
- CA 60-day late · 413d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 30, 2015→ Notified: Nov 16, 2016413d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.