MalwareCapture Stored DataCustomer Data InvolvedData ExfiltratedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Cruzstar LLC.
bd_a05e25677a2f8d3c · schema v1 · pii pii-v1
Full breach record for Cruzstar LLC. →Cruzstar LLC (operating MenuDrive) experienced a malware injection attack on its Desktop ordering site between November 5 and November 28, 2017. The malware was designed to capture credit card information during submission. The incident was contained to the Desktop site and did not affect Mobile ordering. Cruzstar engaged a cybersecurity firm, notified federal law enforcement, and worked with credit card brands. No specific count of affected individuals was disclosed in the notice.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134164
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2018
- Raw hash
- ff4e7bd98233f2b9185ce1c896f300960884ecc48c7d6bbacd597045e44a650d
Reporting entity
- Name
- Cruzstar LLC.norm: cruzstar
Victim entity
- Name
- Cruzstar LLC.norm: cruzstar
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Federal law enforcement of the incident
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.