HackingStolen CredentialsTargetedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPIILowContained
Dick Blick Holdings, Inc.
bd_ffee6a34fe63b0dc · schema v1 · pii pii-v1
Full breach record for Dick Blick Holdings, Inc. →Dick Blick Holdings, Inc. experienced a data security incident where a bad actor modified its website to capture customer payment card data (numbers, CVVs, expiration dates) between March 11, 2020, and December 15, 2020. The company engaged forensic investigators, implemented enhanced security safeguards, and notified affected customers.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4249be22c0a20451Maine State AGfiled 2021-09-13Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-545248
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 13, 2021
- Raw hash
- 7fc3f137c6f0a21d6bfcfa687152358f586accf3b67e05301365877e97b8a373
Reporting entity
- Name
- Dick Blick Holdings, Inc.norm: dick blick
Victim entity
- Name
- Dick Blick Holdings, Inc.norm: dick blick
Incident
- Discovered
- Aug 10, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.