HackingVulnerability ExploitStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowActive
American Barcode and RFID, Inc.
bd_f6cf06fe08ecd458 · schema v1 · pii pii-v1
Full breach record for American Barcode and RFID, Inc. →American Barcode and RFID, Inc. notified the New Hampshire Attorney General's office on August 25, 2009, regarding a security breach affecting consumers in NH. Hackers illegally accessed the Scansmart.com web server during the week of July 27, 2009, exposing customer PII, credit card data, and login credentials. The company restored server integrity and filed a criminal report. The investigation was ongoing at the time of filing.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/rfid-20090825.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2009
- Raw hash
- 4d9cb5832732ac7af70523da0f82b6e08a3aedffd96f6cb98883ffb566d4b95c
Reporting entity
- Name
- American Barcode and RFID, Inc.norm: american barcode and rfid
Victim entity
- Name
- American Barcode and RFID, Inc.norm: american barcode and rfid
Incident
- Discovered
- Jul 27, 2009
- Materiality determined
- —
- Notification sent
- Aug 14, 2009
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.