MalwareStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowResolved
Hammer Nutrition
bd_e69cf3b316f1c648 · schema v1 · pii pii-v1
Full breach record for Hammer Nutrition →Hammer Nutrition notified customers of a data breach affecting payment card data. The intrusion occurred on a third-party website provider's systems between January and October 2018. Attackers placed malware on the servers to access debit/credit card numbers, expiration dates, and CVV codes. No other customer information was accessed. The company engaged a cybersecurity firm to remove malware, installed a web application firewall, and switched to a third-party hosted payment provider.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_73735e3dac8451deOregon State AGfiled 2018-12-21(12d gap)Verified
- bd_cd7859d49b4fabc9Montana State AGfiled 2018-12-14(19d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-143424
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 2, 2019
- Raw hash
- 61fddf850f00669a7ce1548a8fa0d7567741e3fee1d3e94e7927bb293be1567b
Reporting entity
- Name
- Hammer Nutritionnorm: hammer nutrition
- Domain
- hammernutrition.com
Victim entity
- Name
- Hammer Nutritionnorm: hammer nutrition
- Domain
- hammernutrition.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 17, 2018
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via website provider
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.