JB Autosports, Inc suffered a payment card breach in which the details for the customers who used the subispeed.com and ft86speedfactory.com sites between August 1, 2015 through November 9, 2015, were intercepted during transmission and acquired by an unknown party at a Russian IP address.
The hackers got the access to information like customer names, addresses, credit card numbers, credit card expiration dates, CID numbers, CAV2 numbers, CVC2 numbers, and CVV2 numbers (“Customer Information”).
JB Autosports immediately took a number of steps, including implementing live monitoring security services.
Source: https://www.databreaches.net/jb-autosports-customers-notified-of-payment-card-breach/
TPRM report: https://scoringcyber.rankiteo.com/company/jb-automotive
"id": "jba20185123",
"linkid": "jb-automotive",
"type": "Breach",
"date": "01/2016",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Automotive',
'name': 'JB Autosports, Inc',
'type': 'Company'}],
'attack_vector': 'Interception of payment card details during transmission',
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Customer names',
'Addresses',
'Credit card numbers',
'Credit card expiration dates',
'CID numbers',
'CAV2 numbers',
'CVC2 numbers',
'CVV2 numbers']},
'date_detected': '2015-11-09',
'description': 'JB Autosports, Inc suffered a payment card breach in which '
'the details for the customers who used the subispeed.com and '
'ft86speedfactory.com sites between August 1, 2015 through '
'November 9, 2015, were intercepted during transmission and '
'acquired by an unknown party at a Russian IP address.',
'impact': {'data_compromised': ['Customer names',
'Addresses',
'Credit card numbers',
'Credit card expiration dates',
'CID numbers',
'CAV2 numbers',
'CVC2 numbers',
'CVV2 numbers'],
'identity_theft_risk': 'High',
'payment_information_risk': 'High',
'systems_affected': ['subispeed.com', 'ft86speedfactory.com']},
'initial_access_broker': {'entry_point': 'Interception of payment card '
'details during transmission'},
'motivation': 'Financial gain',
'post_incident_analysis': {'corrective_actions': ['Implementing live '
'monitoring security '
'services'],
'root_causes': 'Insecure transmission of payment '
'card data'},
'response': {'enhanced_monitoring': ['Implementing live monitoring security '
'services'],
'remediation_measures': ['Implementing live monitoring security '
'services']},
'threat_actor': 'Unknown party at a Russian IP address',
'title': 'Payment Card Breach at JB Autosports',
'type': 'Payment Card Breach',
'vulnerability_exploited': 'Insecure transmission of payment card data'}