HackingVulnerability ExploitStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedMulti-Stage ChainDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Sark Technologies LLC
bd_f099424e53eb0151 · schema v1 · pii pii-v1
Full breach record for Sark Technologies LLC →Sark Technologies LLC (operating SuperINN.com) disclosed a data breach affecting approximately 43,250 individuals, including 2,882 California residents. Attackers exploited a vulnerability in an image upload function to upload PHP web shells starting September 23, 2018, and later used SQL injection to exfiltrate encrypted cardholder data, names, and addresses through July 16, 2019. The vendor detected the incident on May 26, 2019, removed the shells, patched the vulnerabilities, rotated encryption keys, and engaged forensic investigators and penetration testers.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_c88aea9c362b9388Montana State AGfiled 2019-08-01(1d gap)Verified by operator
- bd_3c1530c52b456d76Washington State AGfiled 2019-07-26(7d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-149410
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 2, 2019
- Raw hash
- e1637e590f0ce510c766f294e98f284fc739f71ae7d97ab45b978d95701a0fe6
Reporting entity
- Name
- BENESCH, FRIEDLANDER, COPLAN & ARONOFF LLPnorm: benesch friedlander coplan aronoff
Victim entity
- Name
- Sark Technologies LLCnorm: sark technologies
Incident
- Discovered
- May 26, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 43,250
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Notice of Data Security Incident to California Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.