HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
PAX Labs, Inc.
bd_ae35c365847dec6d · schema v1 · pii pii-v1
Full breach record for PAX Labs, Inc. →PAX Labs, Inc. disclosed a data breach affecting approximately 6,000 customers of its PAXvapor.com and JUULvapor.com e-commerce sites. Between June 25 and July 22, 2016, unauthorized parties accessed a cloud-based server and installed unauthorized software, exposing payment card data including names, billing/shipping addresses, card numbers, expiration dates, and CVV codes. PAX engaged forensic investigators, removed the malware, enhanced firewall rules, and provided 12 months of free identity protection via AllClear ID.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_cdfab40ab9f0cea1Montana State AGfiled 2016-08-12Candidate
- bd_8bd1ff1a24c029adNew Hampshire State AGfiled 2016-08-11(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-63327
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 12, 2016
- Raw hash
- 62ba5c27cd8d26139e445d509da68eb5279c2123d6db851688375b48124bcf3a
Reporting entity
- Name
- PAX Labs, Inc.norm: pax labs
Victim entity
- Name
- PAX Labs, Inc.norm: pax labs
Incident
- Discovered
- Jul 15, 2016
- Materiality determined
- Aug 12, 2016
- Notification sent
- —
- Affected individuals
- 6,000
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.