HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
The Crucible
bd_f1fea8ad5f4df5a9 · schema v1 · pii pii-v1
Full breach record for The Crucible →The Crucible, an Oakland-based industrial arts organization, disclosed a data breach affecting transactions on TheCrucible.org between April 28, 2019, and February 27, 2020. Malicious code (a skimmer) embedded in an image file on the site captured customer payment data, including credit card numbers, CVVs, and personal information. The Crucible disabled payments, removed the code, and engaged in a forensic investigation. The incident was reported to the California Department of Justice.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190506
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 30, 2020
- Raw hash
- d4e88e73df0c53e3bf61fee9224aa0ab4ea544a4c1d7a35796f38e6a953e2f33
Reporting entity
- Name
- The Cruciblenorm: the crucible
- Domain
- thecrucible.org
Victim entity
- Name
- The Cruciblenorm: the crucible
- Domain
- thecrucible.org
Incident
- Discovered
- Feb 27, 2020
- Materiality determined
- May 29, 2020
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(93 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.