HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Incipio, LLC
bd_a3145b345e29d5d2 · schema v1 · pii pii-v1
Full breach record for Incipio, LLC →Incipio, LLC reported a data breach affecting customers who purchased products between September 26, 2015, and January 29, 2016. An unauthorized party accessed cloud-based e-commerce servers, exposing names, addresses, phone numbers, emails, credit/debit card numbers, expiration dates, and CVVs. The breach was discovered on February 4, 2016, during a software update. Incipio engaged Kroll for one year of free identity monitoring and retained an outside IT security firm to secure servers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-60169
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 22, 2016
- Raw hash
- b445f7a71bb59d66891536af4ca1fc90651df51ff027e1d7b4d959f07fe1c98c
Reporting entity
- Name
- Incipio, LLCnorm: incipio
- Domain
- myincipio.com
Victim entity
- Name
- Incipio, LLCnorm: incipio
- Domain
- myincipio.com
Incident
- Discovered
- Feb 4, 2016
- Materiality determined
- Sep 16, 2016
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.