HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
American Health Care Academy
bd_f8aec2fb07d080f5 · schema v1 · pii pii-v1
Full breach record for American Health Care Academy →CPR AED Course LLC dba American Health Care Academy (AHCA) disclosed a data breach in California involving unauthorized access to its payment card environment. On November 29, 2020, AHCA detected unusual activity and found a webshell allowing access to stored customer data. The breach affected names and debit/credit card numbers temporarily stored for quality assurance. AHCA engaged forensic investigators, reset passwords, and enhanced policies to stop storing payment card data.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_4efa9d455c5eccc2Washington State AGfiled 2021-03-15Candidate
- bd_7758fc79eaa35ddcMontana State AGfiled 2021-03-15Verified
- bd_91ac8b35681b41e2Maine State AGfiled 2021-03-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539125
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 15, 2021
- Raw hash
- 7e0ad0d46e34dffe50f4c06bd4bbf29de3385b6d1132f80d4e0cbda11fceb1c3
Reporting entity
- Name
- American Health Care Academynorm: american health care academy
Victim entity
- Name
- American Health Care Academynorm: american health care academy
Incident
- Discovered
- Nov 29, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1059 Command and Scripting Interpreter
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.