HackingVulnerability ExploitData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowResolved
PupBox
bd_d9e74f7ccefc139c · schema v1 · pii pii-v1
Full breach record for PupBox →PupBox, a business unit of Petco, disclosed a data breach involving an unauthorized plugin on its website that captured and exfiltrated customer personal information, including names, addresses, credit card details (number, expiration, CVV), and passwords. The incident occurred between February 11, 2020, and August 9, 2020. PupBox engaged a cybersecurity firm to investigate and resolved the incident.
California clockDiscovered Sep 2, 2020 → Notified Oct 2, 202030d ✓ CA 60-day OK4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_112e1659397ddbcdOregon State AGfiled 2020-10-02Candidate
- bd_94b2f1b7ca0d521fMontana State AGfiled 2020-10-02Verified by operator
- bd_a35955daeb84c799Washington State AGfiled 2020-10-02Verified
- bd_ac9a1da511d3b286Maine State AGfiled 2020-10-02Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194725
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 2, 2020
- Raw hash
- 6631ea4ba743b706853b49a9df377177e3f2d196032d64b4db6f82897a82476b
Reporting entity
- Name
- Petco Animal Supplies Stores, Inc. (“Petco”)norm: petco animal supplies stores inc petco
Victim entity
- Name
- PupBoxnorm: pupbox
- Domain
- pupbox.com
Incident
- Discovered
- Sep 2, 2020
- Materiality determined
- Oct 2, 2020
- Notification sent
- Oct 2, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input CaptureT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 2, 2020→ Notified: Oct 2, 202030d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.