Menu
Browse

Cyber Incident Victim: Totally Promotional

Date:

Jun 2015

Location:

United States of America

Summary

An Ohio-based promotional products seller experienced a cybersecurity breach where attackers infiltrated systems, compromising customer payment card details and personal information including names, addresses, and verification codes. Unauthorized charges were reported, prompting an investigation which revealed unauthorized access over several weeks. The company halted the attack, secured entry points, removed malware, engaged security experts for audits, and strengthened protections while notifying potentially affected individuals and assuring zero liability for fraudulent transactions.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 3 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 6, 2015, Totally Promotional, an Ohio-based internet seller of promotional products, received customer reports of unauthorized charges on payment cards previously used on its website. This prompted an internal investigation revealing that attackers had forcibly breached the company's systems, potentially accessing customer data between June 23 and July 10. The intrusion allowed unauthorized parties to obtain names, mailing addresses, email addresses, payment card account numbers, card expiration dates, and verification codes. Attackers implanted malware within the compromised systems during their unauthorized access period. The company did not publicly disclose the total number of affected individuals despite external inquiries. Customer notifications later confirmed the temporal scope of data exposure while emphasizing financial protections for victims.

Cyber Incident Image

Totally Promotional terminated the active intrusion upon detection and eliminated the attackers' access point. Security personnel removed all malware deployed during the breach and engaged external cybersecurity experts to conduct forensic analysis. The company implemented enhanced security measures following internal and external audits of its systems. All potentially impacted customers received direct notifications detailing the compromised data types and the attack timeline. Totally Promotional explicitly guaranteed zero liability for fraudulent charges stemming from the incident, assuming responsibility for financial repercussions. These corrective actions occurred alongside unspecified infrastructure hardening initiatives designed to prevent recurrence. The breach investigation concluded without public attribution of attacker identity or motive.

Sources
Sources available to members
1 source