HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Newegg
bd_a5549910906d4da9 · schema v1 · pii pii-v1
Full breach record for Newegg →Newegg Inc. notified California regulators of a data breach affecting customers who placed orders between August 13, 2018, and September 19, 2018. Unauthorized access to checkout servers resulted in the collection of customer names, addresses, and payment card details (including CVV2). Newegg engaged a security firm, removed malicious code, secured servers, and reported the incident to law enforcement and payment networks.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_29aeda114baf466aWashington State AGfiled 2018-11-15Candidate
- bd_95f9e8a39b66d2b3Montana State AGfiled 2018-11-15Verified
- bd_b76f58fed4feb2d0Oregon State AGfiled 2018-11-15Verified
- bd_ca430b5da11acb10South Carolina State AGfiled 2018-11-19(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141826
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 15, 2018
- Raw hash
- 628d5745d51014bfe0a7ab810fc8dc4208a2f3491ea4cf41878b08280ead7dc2
Reporting entity
- Name
- Neweggnorm: newegg
- Domain
- newegg.com
Victim entity
- Name
- Neweggnorm: newegg
- Domain
- newegg.com
Incident
- Discovered
- Sep 18, 2018
- Materiality determined
- Aug 13, 2018
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.