HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
Charles Krug
bd_b75daf576cf7da92 · schema v1 · pii pii-v1
Full breach record for Charles Krug →Charles Krug Winery (C. Mondavi & Family) disclosed a security incident involving its third-party consumer direct sales systems provider, Missing Link Networks, Inc. Between April 1 and April 30, 2015, a third party may have accessed customer names, credit/debit card numbers, payment addresses, passwords, and dates of birth. The breach was discovered on May 27, 2015, and the incident has been contained. Missing Link upgraded its security systems.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-56443
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 18, 2015
- Raw hash
- 23f35f1dd0344cb3708513a9c1669a4cc3c496b86ec86298d95af2fed563838b
Reporting entity
- Name
- Charles Krugnorm: charles krug
- Domain
- charleskrug.com
Victim entity
- Name
- Charles Krugnorm: charles krug
- Domain
- charleskrug.com
Incident
- Discovered
- May 27, 2015
- Materiality determined
- Jun 10, 2015
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.