HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSMediumContained
TOPGOLF CALLAWAY BRANDS CORP.
bd_afa123b162688a93 · schema v1 · pii pii-v1
Full breach record for TOPGOLF CALLAWAY BRANDS CORP. →Topgolf Callaway Brands Corp. reported unusual system activity on August 1, 2023, affecting 5,424 Delaware residents. The incident involved unauthorized access to user profiles, exposing names, addresses, emails, phone numbers, order history, passwords, and security question answers. The company reset passwords, disabled security questions, notified law enforcement, and sent notification letters on August 29, 2023.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_81af480b2da3f803Delaware State AGfiled 2023-08-29Candidate
- bd_137b32dda0b410d8Oregon State AGfiled 2023-08-31(2d gap)Verified
- bd_2c10194f204061aeWashington State AGfiled 2023-08-31(2d gap)Verified
- bd_6607d9ca42a4130cCalifornia State AGfiled 2023-08-31(2d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 2d gap
- bd_aa49a092afae38a0Maine State AGfiled 2023-08-31(2d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/Topgolf-Callaway-DE-App-Sample.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2023
- Raw hash
- 73a711cc0aa6a06384377a51b6d64b8e3b7f767820b00b539af4c5b3f275a6b0
Reporting entity
- Name
- TOPGOLF CALLAWAY BRANDS CORP.norm: topgolf callaway brands
Victim entity
- Name
- TOPGOLF CALLAWAY BRANDS CORP.norm: topgolf callaway brands
Incident
- Discovered
- Aug 1, 2023
- Materiality determined
- —
- Notification sent
- Aug 29, 2023
- Affected individuals
- 5,424
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.