HackingData ExfiltratedCustomer Data InvolvedPIIFINANCIAL_ACCOUNTLowContained
Shoplet.com
bd_cb27885c353ba845 · schema v1 · pii pii-v1
Full breach record for Shoplet.com →Shoplet.com (d.b.a. Ellison Systems, Inc.) disclosed a security incident where a hacker accessed systems on or about December 21, 2012, potentially exposing customer names, addresses, and credit card information. The breach was discovered on January 11, 2013. Shoplet engaged forensic investigators, notified law enforcement, and implemented security controls including a hardware firewall and database relocation. No SSN or DOB was collected.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-41610
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2013
- Raw hash
- 150ae6357c8db2a9ac1a5cd6999018305987e4a0290477d8f40284845e635835
Reporting entity
- Name
- American Express Travel Related Services Company, Inc. and/or its Affiliatesnorm: american express travel related services company inc and or its affiliates
- Domain
- americanexpress.com
Victim entity
- Name
- Shoplet.comnorm: shopletcom
- Domain
- shoplet.com
Incident
- Discovered
- Jan 11, 2013
- Materiality determined
- Dec 21, 2012
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(104 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.