In a cyberattack, hackers stole the names, addresses, and credit card numbers of clients who bought precious metals from JM Bullion.
In July, JM Bullion learned that malicious code had been inserted into its online shopping platform, giving hackers access to the data that users submitted while making a purchase.
Customers who made payments within this time frame and may have been impacted were just informed this week that their information may have been exposed.
Name, address, and payment card information, including account number, card expiration date, and the security code needed to complete purchases, were all hacked.
Source: https://www.itpro.com/security/357638/jm-bullion-hack-payment-details-stolen
TPRM report: https://scoringcyber.rankiteo.com/company/jm-bullion
"id": "jmb23718623",
"linkid": "jm-bullion",
"type": "Data Leak",
"date": "07/2020",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Precious Metals Retailer',
'name': 'JM Bullion',
'type': 'Company'}],
'attack_vector': 'Malicious code inserted into online shopping platform',
'customer_advisories': 'Informed customers who may have been impacted this '
'week',
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': ['Names', 'Addresses'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Addresses',
'Credit card numbers',
'Account numbers',
'Card expiration dates',
'Security codes']},
'date_detected': 'July 2023',
'description': 'Hackers stole the names, addresses, and credit card numbers '
'of clients who bought precious metals from JM Bullion.',
'impact': {'data_compromised': ['Names',
'Addresses',
'Credit card numbers',
'Account numbers',
'Card expiration dates',
'Security codes'],
'payment_information_risk': ['Account number',
'Card expiration date',
'Security code'],
'systems_affected': ['Online shopping platform']},
'initial_access_broker': {'entry_point': 'Online shopping platform'},
'motivation': 'Theft of personal and financial information',
'response': {'communication_strategy': 'Informed customers who may have been '
'impacted this week'},
'threat_actor': 'Hackers',
'title': 'Data Breach at JM Bullion',
'type': 'Data Breach'}