HackingVulnerability ExploitCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Vibram USA, Inc.
bd_f8d9eb0b3107e93c · schema v1 · pii pii-v1
Full breach record for Vibram USA, Inc. →Vibram USA, Inc. disclosed a targeted hacking attack on its third-party hosted website (www.vibramfivefingers.com) occurring between June 6 and July 7, 2014. The attack potentially compromised credit card numbers of customers who made purchases during that period. Social Security numbers and dates of birth were not compromised. Vibram removed malicious code, migrated to a more secure hosting platform, and offered one year of free credit monitoring via Experian to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-46130
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 5, 2014
- Raw hash
- 9b2747090ed5de49436c1a8ebdb49218c0e374a5ec3bc73d4bd7d36938ac1ed7
Reporting entity
- Name
- Vibram USA, Inc.norm: vibram usa
- Domain
- www.vibramfivefingers.com
Victim entity
- Name
- Vibram USA, Inc.norm: vibram usa
- Domain
- www.vibramfivefingers.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Aug 4, 2014
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified state regulators
- Third party
- via Third-party web hosting provider
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.