DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

Bellacor.com, Inc.

bd_94c734474dd42759 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 26, 2012

Filed

Aug 21, 2012

To disclose

26 days

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for Bellacor.com, Inc.

Bellacor.com, Inc. disclosed that an unauthorized third party injected malicious code into its website around June 7, 2012, gaining unlawful access to temporary data files used for e-commerce transactions. The code was discovered and contained on July 26, 2012. Affected data included customer names, addresses, phone numbers, and encrypted credit card numbers with security codes. Bellacor is offering one year of credit monitoring and identity theft resolution services to affected customers.

Incident timeline

undetected · 49 days
discovery → filing · 26 days

Jun 7, 2012

Begins

Jul 26, 2012

Discovered

Aug 21, 2012

Filed

vs. sector median

4 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
California State AGAug 21 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.