HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Spark Pay Online Store
bd_f649ec3a6914c853 · schema v1 · pii pii-v1
Full breach record for Spark Pay Online Store →Spark Pay Online Store, a division of Capital One, N.A., disclosed a security event involving malicious code on a merchant website hosted by Spark Pay. The code allowed fraudsters to obtain customer payment information, including name, address, phone number, email, payment card number, expiration date, and CVV, for transactions made between April 10, 2017, and June 7, 2017. The company removed the code, notified card networks and law enforcement, and offered two years of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_dd1bda0f39e69466Oregon State AGfiled 2017-07-12(6d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100107
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 6, 2017
- Raw hash
- a990e4f672560efa1ad550e10e45c47efa4d01205855ff2b70b015b1593a8486
Reporting entity
- Name
- Spark Pay Online Storenorm: spark pay online store
Victim entity
- Name
- Spark Pay Online Storenorm: spark pay online store
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.