KURU Footwear
ent_ca7acac8868d93122142458c
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
513
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- KURU Footwear
- Normalized
- kuru footwear— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Massachusetts State AGas victim2017-05-15
KURU Footwear reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-05-15. 406 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2017-05-15
KURU Footwear disclosed a cyber-attack involving malware that potentially compromised credit and debit card data (cardholder name, address, card number, expiration date, CVV) for customers who transacted on www.kurufootwear.com between December 20, 2016, and March 3, 2017. The company discovered the breach on February 23, 2017, after investigating unusual activity reported by its credit card processor. Malware was removed, and the FBI is assisting in the investigation.
- Washington State AGas victim2017-05-15
KURU Footwear notified the Washington AG of a cyberattack affecting 513 residents. Malware compromised credit/debit card data (name, address, card number, CVV) from Dec 20, 2016 to Mar 3, 2017. Discovered Feb 23, 2017. Notifications sent May 15, 2017. FBI and forensic experts engaged.
- Montana State AGas victim2017-05-15
KURU Footwear notified customers of a cyber-attack involving malware that compromised payment card data (names, addresses, card numbers, CVVs) from Dec 20, 2016 to Mar 3, 2017. Discovered Feb 23, 2017. Company engaged forensic experts and FBI, removed malware, and implemented additional security procedures.
- New Hampshire State AGas victim2017-05-15
KURU Footwear notified the New Hampshire Attorney General of a cyber-attack involving malware that compromised payment card data (names, addresses, card numbers, CVVs) for 109 NH residents. The incident occurred between Dec 20, 2016, and Mar 3, 2017. KURU engaged forensic investigators and the FBI, removed the malware, and established a hotline.