HackingVulnerability ExploitTargetedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Four Seasons Service & Sales, Inc
bd_9c67e760e61a4956 · schema v1 · pii pii-v1
Full breach record for Four Seasons Service & Sales, Inc →Four Seasons Service & Sales notified customers of a security incident where unauthorized code installed on its website (fstanning.com) between Jan 17 and Feb 15, 2024, captured checkout data including names, addresses, and full payment card details. The code was removed and security enhancements implemented. No specific count of affected individuals was disclosed in the filing.
Vermont clock⏱ VT AG >14 bday25 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6da882720f621670Maine State AGfiled 2024-03-11Candidate
- bd_83dd58769a7197ddMontana State AGfiled 2024-03-11Candidate
- bd_c7ff3ed12ae402ddIndiana State AGfiled 2024-03-11Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-03-11-four-seasons-service-sales-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 11, 2024
- Raw hash
- ff86ee0f9e5b860278a6247e0e94774beb03cbe5e70271e5a187a9f206a0bbe0
Reporting entity
- Name
- Four Seasons Service & Sales, Incnorm: four seasons service sales
- Domain
- fstanning.com
Victim entity
- Name
- Four Seasons Service & Sales, Incnorm: four seasons service sales
- Domain
- fstanning.com
Incident
- Discovered
- Feb 15, 2024
- Materiality determined
- —
- Notification sent
- Mar 11, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.