HackingFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Sony Card Marketing & Services Company
bd_9d3f2877ea2ad968 · schema v1 · pii pii-v1
Full breach record for Sony Card Marketing & Services Company →Sony Card Marketing & Services Company (CMSC) notified the New Hampshire Attorney General on May 28, 2009, of a data security incident affecting 16 New Hampshire residents. Unauthorized copies of credit card numbers, names, and expiration dates were made between February 1, 2009, and April 30, 2009, and emailed to an external account. CMSC discovered the breach on May 13, 2009. No fraudulent use was indicated. Affected individuals were offered one year of complimentary credit monitoring via Debix.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed16 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sony-20090528.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 28, 2009
- Raw hash
- cc365443d4d91949273ac11abfbc1d75dbde1ddfd07d3829a8361c02289bcbc4
Reporting entity
- Name
- Sony Card Marketing & Services Companynorm: sony card marketing
Victim entity
- Name
- Sony Card Marketing & Services Companynorm: sony card marketing
Incident
- Discovered
- May 13, 2009
- Materiality determined
- —
- Notification sent
- Jun 1, 2009
- Affected individuals
- 16
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1530 Data from Cloud Storage Object
- Threat actor
- ExternalFinancial
- Regulator citations
- writing to inform you of a data security incident involving credit card information
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 days(15 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.