HackingTargetedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Running Warehouse LLC
bd_d324255dd74503ba · schema v1 · pii pii-v1
Full breach record for Running Warehouse LLC →Running Warehouse, LLC reported a data security incident where payment card information (names, addresses, card numbers, CVVs) was accessed without authorization on October 1, 2021. The company engaged forensic investigators, notified law enforcement and card brands, and enhanced site security. No specific victim count was disclosed in the filing.
California clockDiscovered Oct 15, 2021 → Notified Dec 16, 202162d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_6bf8934f0ec90678Washington State AGfiled 2021-12-17(1d gap)Verified
- bd_29205aaea2d80515Oregon State AGfiled 2021-12-16(2d gap)Candidate
- bd_50a41abd0cab62baHawaii State AGfiled 2021-12-16(2d gap)Verified
- bd_5cd9bbff700e0379Montana State AGfiled 2021-12-16(2d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 115d gap
- bd_8b2b4b6011e01e85Delaware State AGfiled 2021-12-16(2d gap)Verified
- bd_e66c1d9e5004ca11South Carolina State AGfiled 2021-12-16(2d gap)Verified
- bd_ed278a6c9f0d6163Maine State AGfiled 2021-12-16(2d gap)Verified
- bd_4189f65f175d57c6California State AGfiled 2022-04-12(115d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548688
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 18, 2021
- Raw hash
- ea5e86f2419eb6cda981793dd94830672c200c8f973e17c4fe90bdffc4a99c8f
Reporting entity
- Name
- Running Warehouse LLCnorm: running warehouse
Victim entity
- Name
- Running Warehouse LLCnorm: running warehouse
Incident
- Discovered
- Oct 15, 2021
- Materiality determined
- —
- Notification sent
- Dec 16, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- CA 60-day late · 62d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 15, 2021→ Notified: Dec 16, 202162d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.