HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Aetrex Worldwide, Inc.
bd_a61c8c1f3ff36243 · schema v1 · pii pii-v1
Full breach record for Aetrex Worldwide, Inc. →Aetrex Worldwide, Inc. disclosed a data breach affecting customers who used credit/debit cards on its website between June 22, 2018, and December 4, 2018. An unauthorized third party inserted malicious code to obtain payment card information (name, address, card number, expiration, CVV). Aetrex engaged forensic investigators, removed the code, and implemented security measures. Approximately 55 Rhode Island residents were explicitly identified; total count is undisclosed.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-143964
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 17, 2019
- Raw hash
- aa5f6fa5eccfda27fadfb1593c5f07a891d73db7ded5e57b84e64aff27033400
Reporting entity
- Name
- Aetrex Worldwide, Inc.norm: aetrex worldwide
Victim entity
- Name
- Aetrex Worldwide, Inc.norm: aetrex worldwide
Incident
- Discovered
- Dec 17, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.