HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Fullsteam Software Holdings LLC
bd_ab38ef80dbdd4511 · schema v1 · pii pii-v1
Full breach record for Fullsteam Software Holdings LLC →Event Rental Systems (ERS) disclosed that unauthorized code was inserted into customer website modules to scrape payment card data (card numbers, CVV, expiration dates) and contact information between October 2024 and October 2025. The company removed the code, engaged forensic investigators, notified law enforcement and card brands, and is offering one year of credit monitoring and identity restoration services via Experian to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_717dfdd0ee8232f4Texas State AGfiled 2025-12-16(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-615769
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2025
- Raw hash
- e5e2d37f3ab794e402ff6c40d7dac91d66e6c6ec908a21f69b964726f4ae1265
Reporting entity
- Name
- Fullsteam Software Holdings LLCnorm: fullsteam software
Victim entity
- Name
- Fullsteam Software Holdings LLCnorm: fullsteam software
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 15, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.