HackingRetail & ConsumerRetailVulnerability ExploitCapture App DataData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCILowContained
Polished.com
bd_b871552b83ee6c52 · schema v1 · pii pii-v1
Full breach record for Polished.com →Polished.com (AppliancesConnection.com) reported that an unauthorized party gained access to its website between March 16 and April 23, 2023, acquiring payment card data (name, address, zip code, card number, expiration date, CVV) entered by customers during that period. The company engaged a cybersecurity firm, secured its systems, and enhanced security protocols. Notice sent May 22, 2023.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_243ab28b57b1b35eMaine State AGfiled 2023-05-22Candidate
- bd_254a757d8efec848Montana State AGfiled 2023-05-22Verified
- bd_98c4b857a36d4e67SEC 8-Kfiled 2023-05-26(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567061
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 22, 2023
- Raw hash
- 0fa41640557706bb62e9f1e7356ddba305e301c42b760a95542a86b58eed5965
Reporting entity
- Name
- Polished.comnorm: polishedcom
- Domain
- polished.com
Victim entity
- Name
- Polished.comnorm: polishedcom
- Domain
- polished.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input CaptureT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney General
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.