SureFire Internet Security
bd_b27e07ae6ae346b1 · schema v1 · pii pii-v1
Full breach record for SureFire Internet Security →SureFire Internet Security disclosed that unauthorized access occurred on its website hosted by a third-party provider between May 28 and July 22, 2018. The breach exploited vulnerabilities in PHP and Zend frameworks. Up to 2,511 transactions nationwide were affected, exposing customer names, shipping/billing addresses, and payment card information. Patches were applied on June 22, 2018, and the incident was resolved.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2018
Begins
Aug 29, 2018
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.