HackingVulnerability ExploitCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Ravkoo
bd_d601b80a96140270 · schema v1 · pii pii-v1
Full breach record for Ravkoo →Ravkoo, a digital SaaS platform for prescription fulfillment, detected a cybersecurity attack on its AWS-hosted portal on September 27, 2021. An unauthorized third party attempted to infiltrate the portal. A forensic investigation revealed that certain prescription and health information, including full name, mail address, phone number, and limited medical information, could have been compromised. Social Security Numbers were not accessed. Ravkoo offered one year of complimentary identity monitoring via Kroll.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_4b4f4f311c81eaeeWashington State AGfiled 2022-01-03Candidate
- bd_d90f0cc5f913c2beNew Hampshire State AGfiled 2022-01-03Verified
- bd_e92fcd9fc02d394aMontana State AGfiled 2022-01-03Verified
- bd_b1c21d4401605dcbSouth Carolina State AGfiled 2022-01-04(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 2d gap
- bd_e271be692c34e932Oregon State AGfiled 2022-01-05(2d gap)Verified
- bd_e4f82f363cdb1218Maine State AGfiled 2022-01-05(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-549655
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 3, 2022
- Raw hash
- fdef98f85b459d2e475b030e37cf7644fb5e9ee01b0bc33ea1a9b43abfdc25df
Reporting entity
- Name
- Ravkoonorm: ravkoo
Victim entity
- Name
- Ravkoonorm: ravkoo
Incident
- Discovered
- Sep 27, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.