The Image Group of Toledo, Inc. notified the New Hampshire Attorney General of a security breach affecting 37 state residents. From January to August 2008, hackers exploited an SQL injection vulnerability on the company's e-commerce site to access customer names and credit/debit card information (including CVV). The company shut down the site, conducted a forensic audit, and implemented security measures. Notices were sent to affected individuals on October 6, 2008.
Affected (this filing): 37