PupBox

PupBox

The Washington State Office of the Attorney General reported a data breach involving PupBox, a business unit of Petco Animal Supplies Stores, Inc., on October 2, 2020. The breach, which occurred between February 26, 2020 and July 21, 2020, involved unauthorized access to the PupBox website due to an unauthorized plugin, potentially affecting 1,046 Washington residents. Exposed information included names, email addresses, addresses, credit card numbers, expiration dates, CVV codes, and passwords.

Source: https://www.atg.wa.gov/data-breach-notifications | https://data.wa.gov/resource/sb4j-ca4h.json?id=10682

TPRM report: https://www.rankiteo.com/company/pupbox

"id": "pup111072725",
"linkid": "pupbox",
"type": "Breach",
"date": "2/2020",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 1046,
                        'industry': 'Pet Supplies',
                        'location': 'Washington',
                        'name': 'PupBox',
                        'type': 'Business Unit'}],
 'attack_vector': 'Unauthorized Plugin',
 'data_breach': {'number_of_records_exposed': 1046,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['names',
                                              'email addresses',
                                              'addresses',
                                              'credit card numbers',
                                              'expiration dates',
                                              'CVV codes',
                                              'passwords']},
 'date_detected': '2020-07-21',
 'date_publicly_disclosed': '2020-10-02',
 'description': 'The Washington State Office of the Attorney General reported '
                'a data breach involving PupBox, a business unit of Petco '
                'Animal Supplies Stores, Inc., on October 2, 2020. The breach, '
                'which occurred between February 26, 2020 and July 21, 2020, '
                'involved unauthorized access to the PupBox website due to an '
                'unauthorized plugin, potentially affecting 1,046 Washington '
                'residents. Exposed information included names, email '
                'addresses, addresses, credit card numbers, expiration dates, '
                'CVV codes, and passwords.',
 'impact': {'data_compromised': ['names',
                                 'email addresses',
                                 'addresses',
                                 'credit card numbers',
                                 'expiration dates',
                                 'CVV codes',
                                 'passwords'],
            'systems_affected': ['PupBox website']},
 'initial_access_broker': {'entry_point': 'Unauthorized Plugin'},
 'post_incident_analysis': {'root_causes': 'Unauthorized Plugin'},
 'references': [{'date_accessed': '2020-10-02',
                 'source': 'Washington State Office of the Attorney General'}],
 'title': 'PupBox Data Breach',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Unauthorized Plugin'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.