HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTPCILowContained
Eye Safety Systems, Inc. (ESS)
bd_ca7d3e12f2010745 · schema v1 · pii pii-v1
Full breach record for Eye Safety Systems, Inc. (ESS) →Eye Safety Systems, Inc. (ESS) disclosed a data breach involving unauthorized access to its website, esseyepro.com. An external actor exploited a vulnerability in the website code to exfiltrate customer names, addresses, and payment card information. The incident spanned from November 21, 2017, to July 16, 2019. ESS took the site offline, engaged forensic investigation, and offered credit monitoring services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-149968
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2019
- Raw hash
- 61769c06447459d216c349af399c519dc5bdf1a1dbb77f74c908618649303e8d
Reporting entity
- Name
- Eye Safety Systems, Inc. (ESS)norm: eye safety systems inc ess
- Domain
- esseyepro.com
Victim entity
- Name
- Eye Safety Systems, Inc. (ESS)norm: eye safety systems inc ess
- Domain
- esseyepro.com
Incident
- Discovered
- Jul 16, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.