HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
OXO Products
bd_b04a2cd44987e160 · schema v1 · pii pii-v1
Full breach record for OXO Products →OXO, a consumer goods retailer, disclosed a data breach affecting its e-commerce website. Unauthorized code was inserted into the site on or around July 1, 2018, collecting customer names, billing/shipping addresses, and credit card information. OXO discovered the incident on October 1, 2018, removed the code, engaged forensic consultants, and offered one year of free identity monitoring via Kroll to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141370
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 1, 2018
- Raw hash
- 775ee215a3fd76d50a8e8bbc6529a191b943f889da68546feb43ce3c8bec26b4
Reporting entity
- Name
- OXO Productsnorm: oxo products
- Domain
- oxoproducts.us.com
Victim entity
- Name
- OXO Productsnorm: oxo products
- Domain
- oxoproducts.us.com
Incident
- Discovered
- Oct 1, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.