HackingRetail & ConsumerRetailSkimmerCapture App DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPIIPCILowResolved
First Aid Beauty
bd_da211918bbf1b9ac · schema v1 · pii pii-v1
Full breach record for First Aid Beauty →First Aid Beauty Limited notified California of a web skimming attack on firstaidbeauty.com between April 15 and October 25, 2019. An unauthorized third party placed malicious code on the website that captured customer payment card data (card number, CVV, expiration date) as well as names, addresses, phone numbers, and email addresses. The company took the site offline, removed the code, engaged a data security expert, and offered one year of Experian credit monitoring to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_615fc4de84c07922Oregon State AGfiled 2019-11-08Candidate
- bd_db3165362653ad5bMontana State AGfiled 2019-11-08Verified by operator
- bd_f8a5c17831a5c8b3Washington State AGfiled 2019-11-08Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-184197
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 8, 2019
- Raw hash
- 2de8ede18b09fbe2e24e02ab5dceff639c52cff6ff7fd55900565adac239c4e3
Reporting entity
- Name
- First Aid Beautynorm: first aid beauty
- Domain
- firstaidbeauty.com
Victim entity
- Name
- First Aid Beautynorm: first aid beauty
- Domain
- firstaidbeauty.com
- Industry
- Retail & Consumerllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Nov 8, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPIIPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1059 Command and Scripting InterpreterT1056 Input CaptureT1530 Data from Cloud Storage Object
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.