DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCustomer Data InvolvedIdentity (basic)CredentialsFinancial accountLowContained

iPromo

bd_cfe32523cad22517 · schema v1 · pii pii-v2

Severity

Low

Discovered

Nov 27, 2012

Filed

Dec 3, 2012

To disclose

6 days

Affected

29state residents only

Confidence

66%
Full breach record for iPromo

iPromo notified the NH Attorney General that its website was breached on November 12, 2012, with discovery on November 27, 2012. The incident involved unauthorized exposure of an old customer data file containing PII (names, addresses, emails, passwords) and masked/unmasked credit card data. A maximum of 29 New Hampshire residents were affected. iPromo stated it has taken measures to secure data and is cooperating with legal authorities.

Incident timeline

undetected · 15 days
discovery → filing · 6 days

Nov 12, 2012

Begins

Nov 27, 2012

Discovered

Dec 3, 2012

Filed

vs. sector median

7 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed29 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.