HackingVulnerability ExploitCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Squishable.com, Inc.
bd_c0b7238b2f2d673b · schema v1 · pii pii-v1
Full breach record for Squishable.com, Inc. →Squishable.com, Inc. disclosed a data breach where unauthorized code on its checkout page allowed a third party to capture customer information (name, address, payment card info, email) between May 26 and October 12, 2022. The incident was discovered on October 12, 2022. The company removed the code, engaged forensic investigators, notified law enforcement, and updated website infrastructure.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_26dc2eee49c486e4Montana State AGfiled 2023-03-06Verified by operator
- bd_64f8fc08e15e855bNew Hampshire State AGfiled 2023-03-06Verified
- bd_6bd9ef85cda292c9Maine State AGfiled 2023-03-06Verified
- bd_067484bba6b3d128Washington State AGfiled 2023-03-02(4d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 4d gap
- bd_16ee5ba23e9a9e21Vermont State AGfiled 2023-03-02(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-563972
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 6, 2023
- Raw hash
- 2f55285059b431568a7f1eab3c7de098b590c168928645e53ddafd962e9b80e4
Reporting entity
- Name
- Squishable.com, Inc.norm: squishablecom
- Domain
- squishable.com
Victim entity
- Name
- Squishable.com, Inc.norm: squishablecom
- Domain
- squishable.com
Incident
- Discovered
- Oct 12, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(145 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.