HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
WILTON BRANDS LLC
bd_eef2e597d73594d0 · schema v1 · pii pii-v1
Full breach record for WILTON BRANDS LLC →Wilton Brands LLC disclosed a security incident occurring between July 19, 2012, and October 2, 2012, where a malicious user accessed a server hosting wilton.com and copco.com. The incident exposed customer names, addresses, and payment card information (including CVV2/CVC2/CID). Wilton engaged forensic investigators, notified law enforcement, and changed its payment processing system to stop storing full card data. Affected individuals were offered one year of Experian ProtectMyID services.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_399085c1fc2a54d9California State AGfiled 2013-01-24(43d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-37224
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2012
- Raw hash
- 09472c54c74146678e415c896069d71279ec6577e4fcfdbfb2c843d9a5ea1233
Reporting entity
- Name
- WILTON BRANDS LLCnorm: wilton brands
- Domain
- wilton.com
Victim entity
- Name
- WILTON BRANDS LLCnorm: wilton brands
- Domain
- wilton.com
Incident
- Discovered
- Oct 31, 2012
- Materiality determined
- Dec 10, 2012
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.