The California Office of the Attorney General reported a data breach affecting The Rodgers & Hammerstein Organization on October 15, 2019. The breach occurred on September 9, 2019, when a hacker exploited a vulnerability on the RNH.com website, potentially compromising usernames, email addresses, business contact details, order history, and encrypted passwords.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-183439
TPRM report: https://www.rankiteo.com/company/rodgers-&-hammerstein-an-imagem-company
"id": "rod642072625",
"linkid": "rodgers-&-hammerstein-an-imagem-company",
"type": "Breach",
"date": "9/2019",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Entertainment',
'name': 'The Rodgers & Hammerstein Organization',
'type': 'Organization'}],
'attack_vector': 'Website Vulnerability',
'data_breach': {'data_encryption': 'encrypted passwords',
'personally_identifiable_information': ['usernames',
'email addresses',
'business contact '
'details'],
'type_of_data_compromised': ['usernames',
'email addresses',
'business contact details',
'order history',
'encrypted passwords']},
'date_detected': '2019-09-09',
'date_publicly_disclosed': '2019-10-15',
'description': 'A data breach affecting The Rodgers & Hammerstein '
'Organization was reported by the California Office of the '
'Attorney General on October 15, 2019. The breach occurred on '
'September 9, 2019, when a hacker exploited a vulnerability on '
'the RNH.com website, potentially compromising usernames, '
'email addresses, business contact details, order history, and '
'encrypted passwords.',
'impact': {'data_compromised': ['usernames',
'email addresses',
'business contact details',
'order history',
'encrypted passwords']},
'initial_access_broker': {'entry_point': 'Website Vulnerability'},
'post_incident_analysis': {'root_causes': 'Website Vulnerability'},
'references': [{'date_accessed': '2019-10-15',
'source': 'California Office of the Attorney General'}],
'threat_actor': 'Hacker',
'title': 'Data Breach at The Rodgers & Hammerstein Organization',
'type': 'Data Breach',
'vulnerability_exploited': 'Website Vulnerability'}