DisclosureLens
HackingRetail & ConsumerRetailSkimmerCustomer Data InvolvedData ExfiltratedIdentity (basic)CredentialsFinancial accountFinancial credentialsLowResolved

The Crucible

bd_f1fea8ad5f4df5a9 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

May 30, 2020

To disclose

Affected

Not disclosed

Confidence

65%
Full breach record for The Crucible

The Crucible disclosed a data breach affecting its e-commerce website (TheCrucible.org) between April 28, 2019, and February 27, 2020. Malicious code (a skimmer) on the site captured data inputted during checkout, including names, addresses, emails, phone numbers, usernames, passwords, and full payment card details (card number, expiration, CVV). The organization removed the code, disabled card processing, investigated the incident, and added malware scanning. No specific count of affected individuals was provided.

Incident timeline

Apr 28, 2019

Begins

May 30, 2020

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.