HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedCREDENTIALSPIILowContained
Weaver Fundraising, LLC
bd_ad0ee0c8f07cfa2c · schema v1 · pii pii-v1
Full breach record for Weaver Fundraising, LLC →Weaver Fundraising, LLC d/b/a Trail’s End disclosed a security incident occurring May 3, 2020, discovered May 7, 2020. Unauthorized actors used credentials from other breaches to access user accounts, intercept new passwords sent via email, and redeem Amazon gift cards. Affected data included usernames and passwords. The company reset accounts and blocked attackers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190327
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2020
- Raw hash
- ccb6e6fa4d0551c292ed04ffbf4271ef82157a3c831e518643a7cdff565ac665
Reporting entity
- Name
- Weaver Fundraising, LLCnorm: weaver fundraising
- Domain
- trails-end.com
Victim entity
- Name
- Weaver Fundraising, LLCnorm: weaver fundraising
- Domain
- trails-end.com
Incident
- Discovered
- May 7, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- intend to report this incident to the appropriate law enforcement officials
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 19 days(19 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.