HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Shoppe Object
bd_98df1bf6140834a9 · schema v1 · pii pii-v1
Full breach record for Shoppe Object →The Shoppe Designs, an e-commerce retailer, notified customers on August 15, 2016, of a data breach affecting 313 transactions. The incident involved unauthorized access to the Lemonstandv1 e-commerce platform, resulting in the theft of names, addresses, phone numbers, order details, and 49 credit card numbers. The company shut down the shopping cart, engaged the site developer to create a security patch, and issued breach notifications offering credit monitoring resources.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed313 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/shoppe-designs-20160815.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 15, 2016
- Raw hash
- e75e18c5c151b10819b74219bea050a9b9a73ecbf18b3ed209052f2a9e061644
Reporting entity
- Name
- Shoppe Objectnorm: shoppe object
- Domain
- shoppeobject.com
Victim entity
- Name
- Shoppe Objectnorm: shoppe object
- Domain
- shoppeobject.com
Incident
- Discovered
- Jul 24, 2016
- Materiality determined
- —
- Notification sent
- Aug 15, 2016
- Affected individuals
- 313
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.