HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Trusted Tours & Attractions, LLC
bd_bcfc77003b22c831 · schema v1 · pii pii-v1
Full breach record for Trusted Tours & Attractions, LLC →Trusted Tours & Attractions, LLC experienced a data breach involving unauthorized code injected into its e-commerce website (trustedtours.com). The malicious code operated between March 24, 2019, and June 27, 2019, copying payment card information (including CVV) from purchasers. The company removed the code and is enhancing checkout security. No specific count of affected individuals was disclosed.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1f0f7816528426d0Oregon State AGfiled 2019-07-29Candidate
- bd_557f0c4fd251c8adWashington State AGfiled 2019-07-29Verified
- bd_84a30291ab8f6c65Montana State AGfiled 2019-07-29Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-149294
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 29, 2019
- Raw hash
- 9beacf69c30e4c53ee24a5e61faf7540edf734345e136be5af64f4644766163d
Reporting entity
- Name
- Trusted Tours & Attractions, LLCnorm: trusted tours attractions
Victim entity
- Name
- Trusted Tours & Attractions, LLCnorm: trusted tours attractions
Incident
- Discovered
- Jun 25, 2019
- Materiality determined
- Jun 27, 2019
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.