National Baseball Hall of Fame and Museum
ent_d06dd0e516404cf72a9ff33e
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
213
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- National Baseball Hall of Fame and Museum
- Normalized
- national baseball hall of fame and museum— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- baseballhall.org
Disclosure history (4)newest first
- New Hampshire State AGas victim2019-08-02
National Baseball Hall of Fame and Museum notified NH AG of a data security incident where malicious code was injected into its Web Store between Nov 15, 2018 and May 14, 2019. The code potentially captured customer names, addresses, and credit/debit card info (including CVV). 42 NH residents were affected. The Hall retained forensic investigators, notified law enforcement, removed the code, and alerted credit card brands.
- Massachusetts State AGas victim2019-08-02
National Baseball Hall of Fame and Museum reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-08-02. 213 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2019-08-02
The National Baseball Hall of Fame and Museum experienced a data breach affecting its e-commerce web store (shop.baseballhall.org). An unauthorized third party placed malicious computer code on the system between November 15, 2018, and May 14, 2019. The incident was discovered on June 18, 2019. Affected data included names, addresses, and credit/debit card information including CVV codes. The organization retained forensic investigators, notified law enforcement, removed the malicious code, and alerted credit card brands.
- Montana State AGas victim2019-02-02
The National Baseball Hall of Fame and Museum notified customers that malicious code placed on its web store between Nov 15, 2018 and May 14, 2019 may have captured names, addresses, and credit/debit card details including CVVs. The Hall retained forensic investigators, removed the code, and notified law enforcement.