HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTCREDENTIALSIDENTITY_BASICLowContained
Sugarfina USA, LLC
bd_9ef0158eb8fcad35 · schema v1 · pii pii-v1
Full breach record for Sugarfina USA, LLC →Sugarfina USA, LLC reported a cyber-attack involving unauthorized access to customer payment card information on its website between November 1, 2019, and September 3, 2020. The breach was discovered on January 15, 2021, and confirmed on March 25, 2021. Malicious code allowed access to cardholder names, billing addresses, credit card numbers, expiration dates, CVVs, and usernames/passwords. The filing explicitly identifies 131 Rhode Island residents as affected. Sugarfina secured its website and notified regulators.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_af6dc0ec43bde3f1Oregon State AGfiled 2021-05-25Verified
- bd_cbbc835a8a32a559Montana State AGfiled 2021-05-25Verified
- bd_ce2b887a3ceb24d2Washington State AGfiled 2021-05-25Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541284
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 25, 2021
- Raw hash
- 95c2818dd48de733bcf5242049fae6aad88cdf9fb0000913390857bac8d87881
Reporting entity
- Name
- Sugarfina USA, LLCnorm: sugarfina usa
- Domain
- sugarfina.com
Victim entity
- Name
- Sugarfina USA, LLCnorm: sugarfina usa
- Domain
- sugarfina.com
Incident
- Discovered
- Jan 15, 2021
- Materiality determined
- Mar 25, 2021
- Notification sent
- —
- Affected individuals
- 131
- Data types
- FINANCIAL_ACCOUNTCREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(130 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.