This incident has 0 proposed changes. Know of details that have changed? Submit them Showing Incident 1300 To_xml

SUMMARY

Names, addresses, and credit card numbers exposed by hack
Records 18,432
Record Types CCN NAA
Breach Type Hack
Data Family Electronic
Source Outside
Organization Kiwanis International
Other Affected/Involved Organizations On-Net Services
Lawsuit? NO/UNKNOWN
Data Recovered? NO/UNKNOWN
Arrest? NO/UNKNOWN
Submitted By: Lyger

TIMELINE

DateEvent
None. Add Data Incident Occurred
2008-01-04 Incident Discovered By Organization
2008-01-28 Organization Reports Incident
None. Add Data Organization Mails Notifications
None. Add Data Records Recovered
None. Add Data Lawsuit Filed
None. Add Data Arrest Made

SIMILAR INCIDENTS

recordsdateorganizations
15,700 2000-11-14 Western Union
46,000 2001-04-02 ADDR.com
15,000 2005-04-12 Eastern National, National Park Service
32,000 2006-04-12 Ross-Simons

MAP OF INCIDENT LOCATION

Address: United States
Have a better address for this incident? Suggest it!

suggest a new reference

REFERENCES

suggest a new attachment

ATTACHMENTS

COSTS SUMMARY

Known Actual Costs

No known costs for this incident.

Estimated Costs

Ponemon Institute Direct Costs Estimate 1 $1,105,920.00
  1. Note that these estimates are based on the Ponemon Institute's 2009 direct costs figures from their 2009 Annual Study: Cost of a Data Breach. We multiply $60.00 by the number of records to obtain this figure. Keep in mind that depending on the breach, the direct costs are not always suffered by the breached organizations. In the case of credit card number breaches, the direct costs can often be suffered by banks and card issuers. Also note that this is only an estimate.

PRIMARY SOURCES

Primary Source ID: 1004

add details to this primary source Description
Names, addresses, and credit card numbers exposed by Kiwanis International hack, 149 Maine residents affected.
FilenameSourceResearcher Incident IDs
20080128-Kiwanis_International.pdfMaine Attorney Generald2d <a href='/incidents/show/1300'>1300</a>
RecordsFile DateUploadedUpdated
149 2008-01-28 2009-01-12 17 Jan 10:58
Excerpt
1004

K' ' International Date: January 28, 2008 Dear Ms Conti, AAG, This letter is to inform your agency of our intention to notify state residents of a security breach of our Web site and database. Kiwa...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 1475

add details to this primary source Description
Hawaii breach notification - Kiwanis International reports a SQL injection hack to their online customer database exposes names, addresses, credit card numbers and expiration dates. 36 Hawaii residents affected.
FilenameSourceResearcher Incident IDs
2008-01-28_Kiwanis.pdfHawaii Office of Consumer Protectiond2d <a href='/incidents/show/1300'>1300</a>
RecordsFile DateUploadedUpdated
36 2008-01-28 2009-03-18 13 Apr 21:32
Excerpt
1475

J 9 K" ` International , {1 `_ pi ‘ , * - Q _ 4_ l ·_l`¤; '_ I, _ ` - I -_·,. w.__- · ~' V-i I- -- . _¤ ‘ ,_ ` " `. -- '_ pj, -_ " "-.` . " ' ,. i Date: January 28...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 66

add details to this primary source Description
Kiwanis web site hacked exposing credit card numbers, names, and addresses through SQL Injection attack. 257 Maryland residents affected.
FilenameSourceResearcher Incident IDs
MD_ITU-147132.pdfMaryland Attorney Generalkirniki <a href='/incidents/show/1300'>1300</a>
RecordsFile DateUploadedUpdated
257 2008-01-28 2008-12-04 23 Sep 12:18
Excerpt
66

·II"* x*i w r ·_ gr · ir » ~· - _ » , ~ . V It ti ··· - .:::m¤....,..... ". IWB I1 I S mr. I International ` I tx I*t~ ttt E Date: January 28, 2008 Dear Mr. Williams, This letter is to...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 1856

add details to this primary source Description
North Carolina Data Breach Notification : SQL Injection attack reveals credit card information to hackers.
FilenameSourceResearcher Incident IDs
20080128_kiwanis.pdfNorth Carolina Department of Justice, Consumer Protection Divisiond2d <a href='/incidents/show/1300'>1300</a>
RecordsFile DateUploadedUpdated
570 2008-01-28 2009-06-13 03 Aug 21:20
Excerpt
1856

’ North Camlina Security Breach Reporting Form Pursuant to the Identity Thcft Protection Act of 2005 Nmws = t~f Business Owning 01?Licansing Infonnation Affmted by the PLEASE SUBMIT FORM TO; Branch...

Click here for the Full Details | Download Raw PDF

COMMENTS

New Comment

captcha
Are you human?

Sponsored By: Credant_200x51 Rbs Tenable Zecurion
Use of the DataLossDB, and its exports, RSS feeds, reports, or other materials produced on this site by the Open Security Foundation requires authorization and potential licensing arrangements. For more information, please e-mail officers@opensecurityfoundation.org with a brief summary of how you would like to use this information; product, service, research, etc.
© 2005 - 2012, Open Security Foundation, All Rights Reserved.