HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Barbecue Renew Inc.
bd_d5f550d53b50ae43 · schema v1 · pii pii-v1
Full breach record for Barbecue Renew Inc. →Barbecue Renew Inc., an e-commerce retailer of grill accessories, disclosed a data breach affecting cardholder data (names, addresses, credit card numbers, CVVs) resulting from a cyber attack on its web server. The breach occurred between January 19, 2014, and November 12, 2014, involving multiple instances of exploitation of a web server vulnerability. The company engaged forensic investigators, law enforcement, and provided one year of complimentary identity theft protection services via Kroll to affected customers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-48107
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 16, 2015
- Raw hash
- b4720f219ef4ae791d2590956ce59fcb232b9911073902de900aeadda539cfde
Reporting entity
- Name
- Barbecue Renew Inc.norm: barbecue renew
Victim entity
- Name
- Barbecue Renew Inc.norm: barbecue renew
Incident
- Discovered
- Oct 1, 2014
- Materiality determined
- Dec 17, 2014
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(107 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.