Sark Technologies LLC
ent_5030be3da7b52faa97f3c222
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
48,000
nationwide · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sark Technologies LLC
- Normalized
- sark technologies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- New Hampshire State AGas victim2019-08-02
Sark Technologies LLC (SuperINN.com) notified the NH AG of a data breach affecting ~43,250 individuals. Attackers exploited PHP web shells and SQL injection vulnerabilities in the SuperINN Plus web app (Sept 2018-July 2019) to exfiltrate guest PII and encrypted credit card data. Discovered May 26, 2019. Sark removed shells, patched vulnerabilities, rotated keys, and engaged forensic investigators.
- Massachusetts State AGas victim2019-08-02
Sark Technologies LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-08-02. 2,166 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2019-08-02
Sark Technologies LLC (SuperINN.com) experienced a data breach affecting ~43,250 individuals, including 2,882 California residents. Attackers exploited vulnerabilities in the SuperINN Plus web application, including an image upload function allowing PHP web shell uploads (earliest evidence Sept 23, 2018) and a SQL injection vulnerability (used June-July 2019). Encrypted card numbers, names, addresses, phone numbers, and emails were exfiltrated. The company became aware of the incident on May 26, 2019, and contained it by July 16, 2019.
- Montana State AGas victim2019-08-01
Sark Technologies LLC reported a data breach involving its vendor SuperINN Plus. Attackers exploited a vulnerability in an image upload function and SQL injection to access guest data including names, credit card info, and addresses. The incident window was Sept 2018 to July 2019. Vendor engaged forensic investigators and remediated vulnerabilities.
- Washington State AGas victim2019-07-26
Sark Technologies LLC (SuperINN.com) notified the WA AG of a cyberattack affecting ~48,000 individuals. Attackers exploited a web app vulnerability to upload PHP web shells and used SQL injection to exfiltrate encrypted cardholder data, names, and contact info. Incident window: Sept 23, 2018 - July 16, 2019. Discovered May 26, 2019. 762 WA residents affected.