The Crucible
bd_f1fea8ad5f4df5a9 · schema v1 · pii pii-v1
Full breach record for The Crucible →The Crucible disclosed a data breach affecting its e-commerce website (TheCrucible.org) between April 28, 2019, and February 27, 2020. Malicious code (a skimmer) on the site captured data inputted during checkout, including names, addresses, emails, phone numbers, usernames, passwords, and full payment card details (card number, expiration, CVV). The organization removed the code, disabled card processing, investigated the incident, and added malware scanning. No specific count of affected individuals was provided.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 28, 2019
Begins
May 30, 2020
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.