HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
PFU America
bd_c804fe250fecf56e · schema v1 · pii pii-v1
Full breach record for PFU America →PFU America, Inc. disclosed a data security incident involving its third-party hosted website fujitsuscannerstore.com. Suspicious activity was detected on July 27, 2021, affecting payment card information (names, billing/shipping addresses, card numbers, CVVs) entered between November 30, 2020, and July 27, 2021. The site was taken offline, forensic specialists were hired, and the vendor was engaged. The company implemented additional security controls and offered 12 months of credit monitoring and identity theft protection via IDX to affected individuals.
California clockDiscovered Jul 27, 2021 → Notified Sep 17, 202152d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_55c849d81dd270b0Maine State AGfiled 2021-09-17Candidate
- bd_8eeed4df36947012Montana State AGfiled 2021-09-17Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-545480
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 17, 2021
- Raw hash
- 7c3b3d90d2ba0812ff0d9dab45aaacecd339c6186f05d1ddb0644e00b4936d4c
Reporting entity
- Name
- PFU Americanorm: pfu america
Victim entity
- Name
- PFU Americanorm: pfu america
Incident
- Discovered
- Jul 27, 2021
- Materiality determined
- —
- Notification sent
- Sep 17, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 52d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 27, 2021→ Notified: Sep 17, 202152d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.