Peak Game
bd_cbd185e11c812795 · schema v1 · pii pii-v1
Full breach record for Peak Game →Peak Design disclosed a data compromise involving historical customer service tickets from October 2013 to May 2023. On March 11, 2024, a security gap was inadvertently created when a private server hosting the information was accidentally made externally accessible due to a misconfiguration. The issue was detected by Cybernews on April 25, 2024, and promptly fixed. Peak Design believes the data was compromised on April 1, 2024, by an unauthorized third party. Affected data includes customer names, emails, shipping addresses, order details, and correspondence. No passwords, credit card info, bank info, or SSNs were compromised. Peak Design implemented an IT approval protocol and enhanced training to prevent recurrence.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-586512
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 6, 2024
- Raw hash
- b352a1c5f370bb0b4b7f41dc9f9ab1ae3d6062a35f66ec4808c53d6793507363
Reporting entity
- Name
- Peak Gamenorm: peak game
- Domain
- peakpeakpeak.com
Victim entity
- Name
- Peak Gamenorm: peak game
- Domain
- peakpeakpeak.com
Incident
- Discovered
- Apr 25, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Misconfiguration
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.