HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICMediumContained
Amateur Athletic Union
bd_ef8c672acb9b8d2d · schema v1 · pii pii-v1
Full breach record for Amateur Athletic Union →Amateur Athletic Union (AAU) disclosed a data breach affecting 38,925 California residents. Malicious code was installed on the checkout page of play.aausports.org between October 1, 2018, and July 2, 2019, capturing payment card details (number, expiration, CVV), cardholder names, and addresses. AAU engaged forensic investigators, removed the code, and notified affected individuals and regulators in September 2019.
California clockDiscovered Aug 2, 2019 → Notified Sep 13, 201942d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_188946594fb10928Delaware State AGfiled 2019-09-13Verified
- bd_6abca2ac98691b14Hawaii State AGfiled 2019-09-13Verified
- bd_7dfeedd60232f38eOregon State AGfiled 2019-09-13Candidate
- bd_a145c79fea7b2b15Washington State AGfiled 2019-09-13Verified
Show 1 more filing ↓Show fewer ↑
- bd_b07fe0428d117bacMontana State AGfiled 2019-09-13Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-150546
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 13, 2019
- Raw hash
- 0eb54e7569a39d5a1a9a5965ad283d989c75d9a66878839a65fc98bf6e225779
Reporting entity
- Name
- Amateur Athletic Unionnorm: amateur athletic union
- Domain
- aausports.org
Victim entity
- Name
- Amateur Athletic Unionnorm: amateur athletic union
- Domain
- aausports.org
Incident
- Discovered
- Aug 2, 2019
- Materiality determined
- —
- Notification sent
- Sep 13, 2019
- Affected individuals
- 38,925
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified required state regulatorsNotified consumer reporting agencies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 42d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 2, 2019→ Notified: Sep 13, 201942d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.