HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Tommie Copper
bd_d6f7c607fcb4f138 · schema v1 · pii pii-v1
Full breach record for Tommie Copper →Tommie Copper Inc. reported a data breach affecting California residents from April 25, 2017, to August 29, 2017. Malware inserted into the checkout page of its website collected customer payment information, including names, billing addresses, credit card numbers, expiration dates, and CVVs. Approximately 3,813 California residents were notified. The company engaged forensic investigators, removed the malware, and implemented additional security measures.
California clockDiscovered Aug 11, 2017 → Notified Sep 6, 201726d ✓ CA 60-day OK8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_78d90077a305bf60Oregon State AGfiled 2017-10-06Candidate
- bd_7ec2f9cfb0262cacWashington State AGfiled 2017-10-06Verified
- bd_822ac0968b603adfMontana State AGfiled 2017-10-06Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-102453
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 6, 2017
- Raw hash
- 9d1d56997a0770d73a84c6ed070c396b214de44ca80dfdd92bb388c3de4dec6b
Reporting entity
- Name
- Tommie Coppernorm: tommie copper
Victim entity
- Name
- Tommie Coppernorm: tommie copper
Incident
- Discovered
- Aug 11, 2017
- Materiality determined
- —
- Notification sent
- Sep 6, 2017
- Affected individuals
- 3,813
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notify any required state regulators and the credit reporting agencies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 26d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 11, 2017→ Notified: Sep 6, 201726d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.