HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
Mickey’s Place
bd_c15bf49bbfc47560 · schema v1 · pii pii-v1
Full breach record for Mickey’s Place →The Mick's in Cooperstown, Inc. d/b/a Mickey's Place notified the NH AG of a security incident where unauthorized code was inserted into its website on Feb 7, 2024, diverting credit card data. The breach was discovered on Sep 2, 2024. Up to 8 NH residents were affected. The company engaged a cybersecurity firm, reset passwords, implemented MFA, and offered credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_177e6f77fcaa2c1aMontana State AGfiled 2024-10-25Candidate
- bd_317902df0a7ec893Maine State AGfiled 2024-10-25Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/micks-cooperstown-mickeys-place-20241025.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 25, 2024
- Raw hash
- 39cc4ea0ee4d034f69535c66677a8e32d43ec06c0f8c9d6803e257cf899dc6dd
Reporting entity
- Name
- Mickey’s Placenorm: mickey s place
Victim entity
- Name
- Mickey’s Placenorm: mickey s place
Incident
- Discovered
- Sep 2, 2024
- Materiality determined
- Sep 20, 2024
- Notification sent
- Oct 25, 2024
- Affected individuals
- 8
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.