HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Mama Mio
bd_edb49df625b20e04 · schema v1 · pii pii-v1
Full breach record for Mama Mio →Mama Mio US, Inc. disclosed a cyber-attack on its website (mioskakespeare.com) occurring between April 29, 2015, and July 28, 2015. The breach compromised customer personal data including names, emails, billing/shipping addresses, and full credit/debit card details (number, expiry, CVV). The company engaged forensic investigators, notified credit card issuers and acquiring banks, cancelled affected cards, and reported the incident to UK regulators (ICO, Action Fraud) and the California State Regulator. No specific count of affected individuals was provided in the filing.
California clockDiscovered Jul 28, 2015 → Notified Jul 28, 20150d ✓ CA 60-day OK7 days discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-57280
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 4, 2015
- Raw hash
- 102a70990092230a0e6c5884f375bde25a8806383571cc02303d522798cfba54
Reporting entity
- Name
- Mama Mionorm: mama mio
- Domain
- mamamiouk.com
Victim entity
- Name
- Mama Mionorm: mama mio
- Domain
- mamamiouk.com
Incident
- Discovered
- Jul 28, 2015
- Materiality determined
- —
- Notification sent
- Jul 28, 2015
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Information Commissioner's OfficeNotified Action Fraud (The National Fraud and Cyber Crime Reporting Centre)Notified your State Regulator
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 28, 2015→ Notified: Jul 28, 20150d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.