HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowActive
Vendini, Inc.
bd_e51aec51fd76c236 · schema v1 · pii pii-v1
Full breach record for Vendini, Inc. →Vendini, Inc. notified patrons of a cybersecurity incident detected on April 25, 2013, involving unauthorized access to databases in late March 2013. A third-party criminal actor used hacking technologies to access personal information, including names, addresses, emails, phone numbers, and credit card numbers/expiry dates. The breach affected patrons of entertainment venues across the U.S. and Canada. Vendini engaged forensic experts, enhanced security, and notified merchant banks and credit card companies. Notification was delayed to support federal law enforcement.
California clockDiscovered Apr 25, 2013 → Notified May 22, 201327d ✓ CA 60-day OK29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-41854
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 24, 2013
- Raw hash
- 616922117a925a56ede0e1eb2d80e1f797262fe61bfc49bf5a638550a44d0731
Reporting entity
- Name
- Vendini, Inc.norm: vendini
- Domain
- vendini.com
Victim entity
- Name
- Vendini, Inc.norm: vendini
- Domain
- vendini.com
Incident
- Discovered
- Apr 25, 2013
- Materiality determined
- —
- Notification sent
- May 22, 2013
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- cooperating with federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 27d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 25, 2013→ Notified: May 22, 201327d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.