HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
Running Warehouse LLC
bd_e66c1d9e5004ca11 · schema v1 · pii pii-v1
Full breach record for Running Warehouse LLC →Running Warehouse, LLC notified South Carolina consumers of a data security incident affecting payment card information (name, address, card number, expiration, CVV). The incident occurred on October 1, 2021, and was discovered on October 15, 2021. The company engaged forensic investigators, reported to payment card brands and law enforcement, and enhanced site security. Notification letters were sent on December 16, 2021.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_29205aaea2d80515Oregon State AGfiled 2021-12-16Candidate
- bd_50a41abd0cab62baHawaii State AGfiled 2021-12-16Verified
- bd_5cd9bbff700e0379Montana State AGfiled 2021-12-16Verified
- bd_8b2b4b6011e01e85Delaware State AGfiled 2021-12-16Verified
Show 4 more filings ↓Show fewer ↑up to 117d gap
- bd_ed278a6c9f0d6163Maine State AGfiled 2021-12-16Verified
- bd_6bf8934f0ec90678Washington State AGfiled 2021-12-17(1d gap)Verified
- bd_d324255dd74503baCalifornia State AGfiled 2021-12-18(2d gap)Verified
- bd_4189f65f175d57c6California State AGfiled 2022-04-12(117d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/RunningWarehouse.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2021
- Raw hash
- 0be5c20a9d470ce76495eea7722b64a5b252424426daecc910a21a093a85518e
Reporting entity
- Name
- Running Warehouse LLCnorm: running warehouse
Victim entity
- Name
- Running Warehouse LLCnorm: running warehouse
Incident
- Discovered
- Oct 15, 2021
- Materiality determined
- —
- Notification sent
- Dec 16, 2021
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.