DisclosureLens
HackingRetail & ConsumerRetailVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

PLAE, Inc.

bd_d5af1ad9551b781b · schema v1 · pii pii-v1

Severity

Low

Discovered

May 10, 2018

Filed

Jun 4, 2018

To disclose

25 days

Affected

Not disclosed

Linked

3 filings

Confidence

65%
Full breach record for PLAE, Inc.

PLAE INC. experienced a cyber-attack between March 15, 2018, and May 11, 2018, involving real-time scraping of payment card data from its website. The incident affected customers who placed online orders during this period. Compromised data included names, addresses, phone numbers, emails, credit card numbers, and security codes. PLAE discovered the breach on May 10, 2018, contained the attack, and engaged the US Secret Service. Identity theft protection services were offered to affected individuals.

California clockDiscovered May 10, 2018Notified May 29, 201819d CA 60-day OK25 days discovery → filing

Incident timeline

undetected · 56 days
discovery → filing · 25 days

Mar 15, 2018

Begins

May 10, 2018

Discovered

Jun 4, 2018

Filed

vs. sector median

4 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
California State AGJun 4 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.