Sark Technologies LLC
bd_f099424e53eb0151 · schema v1 · pii pii-v1
Full breach record for Sark Technologies LLC →Sark Technologies LLC (SuperINN.com) experienced a data breach affecting ~43,250 individuals, including 2,882 California residents. Attackers exploited vulnerabilities in the SuperINN Plus web application, including an image upload function allowing PHP web shell uploads (earliest evidence Sept 23, 2018) and a SQL injection vulnerability (used June-July 2019). Encrypted card numbers, names, addresses, phone numbers, and emails were exfiltrated. The company became aware of the incident on May 26, 2019, and contained it by July 16, 2019.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 23, 2018
Begins
May 26, 2019
Discovered
Aug 2, 2019
Filed
vs. sector median
9 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- New Hampshire State AGbd_1e1572f873d07f132019-08-02Verified
- Massachusetts State AGbd_49d624cae94ccd212019-08-02Verified
- Montana State AGbd_c88aea9c362b93882019-08-01 · +1dVerified by operator
- Washington State AGbd_3c1530c52b456d762019-07-26 · +7dCandidate
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 26 (WA), last Aug 2 (CA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.