HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Lazarus Naturals
bd_c0da585491bdcca2 · schema v1 · pii pii-v1
Full breach record for Lazarus Naturals →Lazarus Naturals (Etz Hayim Holdings, SPC) disclosed a data breach occurring between September 5 and 14, 2020. Malicious code was inserted on the checkout page to capture customer payment card information and PII. The company engaged forensic investigators, removed the code, restructured server architecture, and migrated to a new platform. Credit monitoring was offered to affected customers.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_463c8204d5747ff5Oregon State AGfiled 2020-11-30Candidate
- bd_72e3fb110935c997Maine State AGfiled 2020-11-30Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-196610
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 30, 2020
- Raw hash
- 62189483cc1d0a2c9f13d6c08d266f7b5295131ab00ff9c871307e29a8ab3568
Reporting entity
- Name
- Lazarus Naturalsnorm: lazarus naturals
- Domain
- lazarusnaturals.com
Victim entity
- Name
- Lazarus Naturalsnorm: lazarus naturals
- Domain
- lazarusnaturals.com
Incident
- Discovered
- Sep 14, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.