HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
American Pharmacists Association
bd_ec74cd36d19272a1 · schema v1 · pii pii-v1
Full breach record for American Pharmacists Association →American Pharmacists Association (APhA) disclosed a cybersecurity incident where its website was defaced on May 28, 2012. Unauthorized access occurred between April 23 and May 28, 2012, resulting in the exfiltration of customer data including names, addresses, credit card numbers, and expiration dates. A separate notification indicated some records included driver's license numbers. APhA shut down servers, engaged forensic investigators, and notified law enforcement. Affected individuals were offered credit monitoring services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-32315
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 18, 2012
- Raw hash
- b7ed9413a2b0afb2e3c010fb2391ee27600dd3e4f8c2d860be8309a1802c0459
Reporting entity
- Name
- American Pharmacists Associationnorm: american pharmacists
- Domain
- aphanet.org
Victim entity
- Name
- American Pharmacists Associationnorm: american pharmacists
- Domain
- aphanet.org
Incident
- Discovered
- May 28, 2012
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.