HackingVulnerability ExploitMulti-Stage ChainTargetedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Northwoods League, Inc.
bd_fa9ff0697b4700da · schema v1 · pii pii-v1
Full breach record for Northwoods League, Inc. →Northwoods League, Inc. disclosed a July 2024 data breach affecting its ticketing service. An unknown threat actor exploited the checkout tool, potentially accessing credit card numbers and PII (names, addresses, emails, phones) for purchases through October 9, 2024. The company replaced the checkout tool, engaged forensic investigators, and partnered with IDX for consumer support. No specific affected individual count was provided.
Vermont clock✗ VT AG >45 bday23 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3b25833770741b3fMontana State AGfiled 2024-12-09(1d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-12-10-northwoods-league-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 10, 2024
- Raw hash
- 59323aa6b57aa9e8b746375e2586ab06114ea146784ad6db2a02df1e4858a884
Reporting entity
- Name
- Northwoods League, Inc.norm: northwoods league
Victim entity
- Name
- Northwoods League, Inc.norm: northwoods league
Incident
- Discovered
- Jul 1, 2024
- Materiality determined
- Dec 10, 2024
- Notification sent
- Dec 10, 2024
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 weeks(162 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.