HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Kayser-Roth, Inc.
bd_a84a721cdf83e564 · schema v1 · pii pii-v1
Full breach record for Kayser-Roth, Inc. →Kayser-Roth Corporation (via third-party vendor Aptos Inc.) disclosed a breach affecting approximately 90,548 customers. The incident occurred between February 2016 and December 2016, involving unauthorized access to payment card data and customer PII (names, addresses, emails). The breach was discovered on February 6, 2017. Response actions included engaging Mandiant for forensics, notifying the FBI, and notifying card issuers. No evidence of fraud was found.
California clockDiscovered Feb 6, 2017 → Notified Jun 1, 2017115d ✗ CA 60-day late21 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_08f13f5794e8a6eaSouth Carolina State AGfiled 2017-07-05Verified
- bd_b53bf980330e0a42Montana State AGfiled 2017-07-03(2d gap)Verified
- bd_c8f623bb36a6f011Oregon State AGfiled 2017-06-20(15d gap)Candidate
- bd_07a3d2a27cc5b7c6Montana State AGfiled 2017-08-09(35d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100086
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 5, 2017
- Raw hash
- 00c5b579c9af420a941240421c49a4a41139ed4fc74c03884ff5ff0268ef6fa7
Reporting entity
- Name
- Kayser-Roth, Inc.norm: kayser roth
Victim entity
- Name
- Kayser-Roth, Inc.norm: kayser roth
Incident
- Discovered
- Feb 6, 2017
- Materiality determined
- —
- Notification sent
- Jun 1, 2017
- Affected individuals
- 90,548
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the FBI Cyber division and the U.S. Department of JusticeAptos received an official request from the FBI to defer disclosure for a minimum of 60 days
- Third party
- via Aptos Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 21 weeks(149 days from discovery to filing)
- Compliance flags
- CA 60-day late · 115d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 6, 2017→ Notified: Jun 1, 2017115d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.