This incident has 0 proposed changes. Know of details that have changed? Submit them Showing Incident 1230 To_xml

SUMMARY

SQL Injection Hack exposes names, credit card numbers, CVV codes, of hundreds.
Records 4,943
Record Types CCN
Breach Type Hack
Data Family Electronic
Source Outside
Organization The Image Group of Toledo, Inc.
Other Affected/Involved Organizations None
Lawsuit? NO/UNKNOWN
Data Recovered? NO/UNKNOWN
Arrest? NO/UNKNOWN
Submitted By: d2d

TIMELINE

DateEvent
2008-08-06 Incident Occurred
2008-08-26 Incident Discovered By Organization
2008-09-29 Organization Reports Incident
2008-10-06 Organization Mails Notifications
None. Add Data Records Recovered
None. Add Data Lawsuit Filed
None. Add Data Arrest Made

SIMILAR INCIDENTS

recordsdateorganizations
2,800 2005-12-12 Aid To The Church In Need
3,800 2005-12-19 Guidance Software
14,277 2006-04-28 U.S. Department of Defense, Tricare Management Activity
9,300 2006-05-19 Unknown Organization, Frost Bank

MAP OF INCIDENT LOCATION

Address: United States
Have a better address for this incident? Suggest it!

suggest a new reference

REFERENCES

suggest a new attachment

ATTACHMENTS

COSTS SUMMARY

Known Actual Costs

No known costs for this incident.

Estimated Costs

Ponemon Institute Direct Costs Estimate 1 $296,580.00
  1. Note that these estimates are based on the Ponemon Institute's 2009 direct costs figures from their 2009 Annual Study: Cost of a Data Breach. We multiply $60.00 by the number of records to obtain this figure. Keep in mind that depending on the breach, the direct costs are not always suffered by the breached organizations. In the case of credit card number breaches, the direct costs can often be suffered by banks and card issuers. Also note that this is only an estimate.

PRIMARY SOURCES

Primary Source ID: 147

add details to this primary source Description
Breach notification letter from the Image Group.
FilenameSourceResearcher Incident IDs
MD_ITU159174.pdfMaryland Attorney Generalkirniki <a href='/incidents/show/1230'>1230</a>
RecordsFile DateUploadedUpdated
258 2008-09-29 2008-12-04 23 Sep 12:46
Excerpt
147

Toledo-Cleveland·P1ffsburgh·AnnArb¤rg€ Ip .,` stm D `.,.,._ Mg ,,,..,,..,.,,,$_m @,&~...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 294

add details to this primary source Description
Breach notification letter sent from the Image Group to New Hampshire.
FilenameSourceResearcher Incident IDs
NH_imagegroup.pdfNew Hampshire Consumer Protection & Antitrust Bureaukirniki <a href='/incidents/show/1230'>1230</a>
RecordsFile DateUploadedUpdated
37 2008-09-29 2008-12-04 23 Sep 14:55
Excerpt
294

o .. ,WW. . . ..Q.. ®‘??¥*? *?*i H #?·i Z v.»W —.w.»w.1iweirrio<;eaqr<;»o:;¤ne? i‘:ii~¢d»> L.!·av<·v3::¤ September 29, EGGS Cnrysmahzzaiyn...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 923

add details to this primary source Description
Personal information about name, address, social security number accessed by a hacker, using SQL injection
FilenameSourceResearcher Incident IDs
20080929-Image_Group.pdfMaine Attorney Generald2d <a href='/incidents/show/1230'>1230</a>
RecordsFile DateUploadedUpdated
Not yet entered 2008-09-29 2009-01-12 29 Jan 14:36
Excerpt
923

fsé ig; »: V; ··V. 3 s A, _ Tolecio·Cle»¤ ond · M rglvftnn A rb r $ E; VV\N\NvThSlmGgQgrOUp`n€i September 29, 2008 [urp¤mt¤He¤dqumters: liiitmpnmtetlma in anu: I "°““"l·l’“ *3528 Mr. Steven Rowe...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 1247

add details to this primary source Description
FilenameSourceResearcher Incident IDs
VA_09292008_the_image_group.pdfVirginia Attorney Generaljkouns <a href='/incidents/show/1230'>1230</a>
RecordsFile DateUploadedUpdated
Not yet entered 2008-09-29 2009-02-03 09 Feb 01:13
Excerpt
1247

· 2 · 0‘ fi; i J, __ fg · " * ine: rt t;:;;=5;;;_;n_i;g t¤:g· Septe1nher29,200S Ji: ri`. r:r;J.;..` ` l t ' ’‘ Mr. Robert McDonnell ’” ' " Office ofthe Attorney General l`...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 1575

there is/are 1 updates pending moderation for this source Description
New York Data Breach Notification : SQL injection attack on database resulted in name and credit card information being disclosed.
FilenameSourceResearcher Incident IDs
Image-Group-of-Toledo-OTHER.pdfNew York State Consumer Protection Boardcwalsh <a href='/incidents/show/1230'>1230</a>
RecordsFile DateUploadedUpdated
202 2008-09-29 2009-05-07 06 Jul 08:37
Excerpt
1575

X Q- ` . » Q- N Q» J lm »w»»x·v.iiwezeim<;:;;gogsr>air>_not September 29, 2008 omnnrrmdqmnm l25SC¤m¤mze0m¤ anna: “°‘°'“·°“ *35*** Ms. Mindy Bockstein “"°*""·”“·““’ New York Consumer Prote...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 2206

add details to this primary source Description
Massachusetts Data Breach Notification : Website hack allowed access to personal information.
FilenameSourceResearcher Incident IDs
20080929_the_image_group.pdfMassachusetts Attorney Generald2d <a href='/incidents/show/1230'>1230</a>
RecordsFile DateUploadedUpdated
106 2008-08-29 2009-08-08 19 Aug 17:01
Excerpt
2206

Vl/VV\N.lll9lmOg€gfOUp.D€l September 29, 2008 (mpumellmdmmus t25SC¤p¤u•eum E0.Bnxll47 ‘*""‘*°“ ‘”’“ Ms. Martha Coakley ‘°°*"’·"“·”°° Office of the Attorney General ‘°'*”°“°°°·°‘°·"" One Ashburton Pla...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 2111

add details to this primary source Description
Massachusetts Data Breach Notification : Hack of website allowed access to personal information.
FilenameSourceResearcher Incident IDs
20080929_the_image_group_MA.pdfMassachusetts Attorney Generald2d <a href='/incidents/show/1230'>1230</a>
RecordsFile DateUploadedUpdated
106 2008-08-29 2009-08-08 19 Aug 17:01
Excerpt
2111

September 29, 2008 tnpmH¤ml¤p¤n¤=; l2SS€upn¤¤eDn¤ RD.BuxlI4T “‘*"l“" *35** Ms. Martha Coakley “'°°*"’·“‘*“°° Office of the Attorney General ‘°'F”°°”°°·“"°·“"‘ One Ashburton Place *"""·“"~”°" Boston,...

Click here for the Full Details | Download Raw PDF

COMMENTS

by d2d [Data Loss Maven] on 2009-02-08 (about 3 years ago)

removed total affected of 297, clearly it wasn't right (from primary sources data)

New Comment

captcha
Are you human?

Sponsored By: Credant_200x51 Rbs Tenable Zecurion
Use of the DataLossDB, and its exports, RSS feeds, reports, or other materials produced on this site by the Open Security Foundation requires authorization and potential licensing arrangements. For more information, please e-mail officers@opensecurityfoundation.org with a brief summary of how you would like to use this information; product, service, research, etc.
© 2005 - 2012, Open Security Foundation, All Rights Reserved.