HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
A&A Global Imports, Inc
bd_e4bdcbdac5bda60e · schema v1 · pii pii-v1
Full breach record for A&A Global Imports, Inc →A&A Global Imports, Inc. reported a cybersecurity incident where unauthorized code was placed on its website, potentially capturing customer checkout data (names, passwords, credit card details) between August 2017 and January 2019. The company engaged forensic investigators, removed the code, migrated its platform, and offered 12 months of credit monitoring. Law enforcement was notified.
California clockDiscovered Aug 17, 2018 → Notified Jan 9, 2019145d ✗ CA 60-day late21 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_ca6d8911439ebdf0Oregon State AGfiled 2019-01-14Verified
- bd_cb2c205723fdf64bWashington State AGfiled 2019-01-09(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-143824
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2019
- Raw hash
- 7242961624d27d586c8102ec90efb4f35e4886f28ada02cab2f7051f72271b05
Reporting entity
- Name
- A&A Global Imports, Incnorm: a a global imports
Victim entity
- Name
- A&A Global Imports, Incnorm: a a global imports
Incident
- Discovered
- Aug 17, 2018
- Materiality determined
- —
- Notification sent
- Jan 9, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(150 days from discovery to filing)
- Compliance flags
- CA 60-day late · 145d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 17, 2018→ Notified: Jan 9, 2019145d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.