HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
Deltek, Inc.
bd_fe27a2858b6b7dba · schema v1 · pii pii-v1
Full breach record for Deltek, Inc. →Deltek, Inc. disclosed a security incident involving its GovWin IQ website, where unauthorized access occurred between July 3, 2013, and November 2, 2013. The attacker exploited a vulnerability to access customer data, including names, billing addresses, credit card numbers, and login credentials. Deltek remedied the vulnerability, engaged forensic investigators, notified credit card issuers, and provided one year of TransUnion credit monitoring to affected individuals. The primary suspect was arrested.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-44769
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 10, 2014
- Raw hash
- 3f924fde199fdda5c599c507b227b1e4a4803a94945ac358401b148cbcdca09a
Reporting entity
- Name
- Deltek, Inc.norm: deltek
- Domain
- deltek.com
Victim entity
- Name
- Deltek, Inc.norm: deltek
- Domain
- deltek.com
Incident
- Discovered
- Mar 13, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Cooperating with law enforcement’s investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.