HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Net32, Inc.
bd_a4e264a527ee3846 · schema v1 · pii pii-v1
Full breach record for Net32, Inc. →Net32, Inc. disclosed that a third-party vendor misused its log-in credentials to improperly access Net32's order management system between September 22 and September 25, 2018. The vendor used these credentials to generate anomalous order activity, revealing credit card information. Net32 suspended the vendor's credentials on September 25 and required all vendors to reset passwords. Personal information, potentially including credit card numbers, may have been exposed. Net32 offered free credit monitoring via Experian to affected customers.
California clockDiscovered Sep 22, 2018 → Notified Sep 27, 20185d ✓ CA 60-day OK5 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ec5d21b48b1c6786Montana State AGfiled 2018-10-25Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141126
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 25, 2018
- Raw hash
- e1bcc2818105e6c9baabef106988a85b933d000a314b7cf9717d4ed656883a53
Reporting entity
- Name
- Net32, Inc.norm: net32
Victim entity
- Name
- Net32, Inc.norm: net32
Incident
- Discovered
- Sep 22, 2018
- Materiality determined
- —
- Notification sent
- Sep 27, 2018
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Third-party vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 5d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 22, 2018→ Notified: Sep 27, 20185d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.