HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
International E-Z UP, Inc.
bd_93bf8eb23055d585 · schema v1 · pii pii-v1
Full breach record for International E-Z UP, Inc. →International E-Z UP, Inc. reported a data breach affecting customers who made payments on its e-commerce site between May 11, 2018, and August 2, 2018. Malicious code was inserted into the site, capturing credit card numbers, CVVs, and expiration dates. The company removed the code, secured the site, and notified affected individuals, including specific notices for residents of Rhode Island, North Carolina, and Maryland.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-143759
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 11, 2019
- Raw hash
- 8c7cf23491e0a0f5c3188739f3384a43b6f2b7228567be0c772c86625205a89e
Reporting entity
- Name
- International E-Z UP, Inc.norm: international e z up
Victim entity
- Name
- International E-Z UP, Inc.norm: international e z up
Incident
- Discovered
- Oct 8, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(95 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.