HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Carvin Audio
bd_d533a09a64f4a304 · schema v1 · pii pii-v1
Full breach record for Carvin Audio →Carvin Software, LLC disclosed that unauthorized parties copied files from its network between February 22 and March 9, 2023. The incident was detected on March 9, 2023. Affected data included names and other personal information. The company isolated systems, investigated the breach, notified law enforcement, and offered credit monitoring to affected individuals.
California clockDiscovered Mar 9, 2023 → Notified May 2, 202354d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_1a019f0dc61bda8dMontana State AGfiled 2023-05-02Candidate
- bd_607315800f92712cMaine State AGfiled 2023-05-02Verified
- bd_8d65e705d3015f8dOregon State AGfiled 2023-05-02Verified
- bd_b7d614e4113908f9Washington State AGfiled 2023-05-02Verified
Show 5 more filings ↓Show fewer ↑up to 17d gap
- bd_f4854483539e0301Delaware State AGfiled 2023-05-02Verified
- bd_298585b51b9c0d49New Hampshire State AGfiled 2023-05-09(7d gap)Verified
- bd_e3da1816f9fc0621California State AGfiled 2023-05-17(15d gap)Verified
- bd_a5615bf8e5598a2bCalifornia State AGfiled 2023-05-19(17d gap)Verified
- bd_b9b266fe06fc8de9Vermont State AGfiled 2023-05-19(17d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-566252
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 2, 2023
- Raw hash
- 92bdf727a89055f2b65e7048d32c8a148b9aa49b8b986a16bf246f0277ea8a72
Reporting entity
- Name
- Carvin Audionorm: carvin audio
- Domain
- carvinaudio.com
Victim entity
- Name
- Carvin Audionorm: carvin audio
- Domain
- carvinaudio.com
Incident
- Discovered
- Mar 9, 2023
- Materiality determined
- —
- Notification sent
- May 2, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 54d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 9, 2023→ Notified: May 2, 202354d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.