HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Bulletproof 360, Inc.
bd_a6e6169f1945caa5 · schema v1 · pii pii-v1
Full breach record for Bulletproof 360, Inc. →Bulletproof 360, Inc. disclosed a data breach affecting payment card information (name, card number, expiration, CVV) for customers who made online transactions between October 26, 2016, and September 5, 2017. An unknown third party compromised the e-commerce system by inserting unauthorized code. The company engaged a security firm, notified law enforcement, and removed the malicious code.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ca7be4e95ab289bfOregon State AGfiled 2017-09-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101923
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2017
- Raw hash
- 3753983bdfcde05a6003e2c59ec07ff68deeec16cec4db8ae1dcb88f0dcf6137
Reporting entity
- Name
- Bulletproof 360, Inc.norm: bulletproof 360
- Domain
- bulletproof.com
Victim entity
- Name
- Bulletproof 360, Inc.norm: bulletproof 360
- Domain
- bulletproof.com
Incident
- Discovered
- Aug 1, 2017
- Materiality determined
- Sep 15, 2017
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.