Surefire USA
bd_9acaac05c07b1455 · schema v1 · pii pii-v1
Full breach record for Surefire USA →SureFire disclosed that unauthorized access was gained to its website server on or about May 28, 2018, via a vulnerability in PHP and Zend frameworks. The breach affected up to 2,511 transactions nationwide between May and July 2018, exposing consumer names, addresses, and payment card information. Patches were applied and monitoring increased.
J jump to incidentP pin to compareR raw source
Incident timeline
May 1, 2018
Begins
May 28, 2018
Discovered
Aug 19, 2018
Filed
vs. sector median
+4 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.