HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
BraceAbility, Inc.
bd_99609ca4c6c3ed30 · schema v1 · pii pii-v1
Full breach record for BraceAbility, Inc. →BraceAbility, Inc. disclosed a security incident affecting its online ordering website. Between September 24, 2016, and November 28, 2016, credit and debit card data (including card numbers, verification codes, and expiration dates) of customers making online purchases may have been compromised. The company engaged forensic experts, corrected the vulnerability, and offered one year of free credit monitoring through Equifax.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fc8f4aff59138d3bMontana State AGfiled 2016-12-13Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65407
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 13, 2016
- Raw hash
- c9c528e8326ccd60181662e5e4728df77c856eb7cb50329300a89e223cd83dd3
Reporting entity
- Name
- BraceAbility, Inc.norm: braceability
Victim entity
- Name
- BraceAbility, Inc.norm: braceability
Incident
- Discovered
- Oct 28, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.