2017 Provo Craft & Novelty (Cricut) — e-commerce environment incident
Data compromised
Online order and payment-card data classes per state-filed consumer notices
Technical writeup
Provo Craft & Novelty, Inc. d/b/a Cricut notified California and other regulators of a May 27, 2017, cybersecurity incident affecting its e-commerce environment, with substitute and consumer letters appearing from October 2017 onward. Public breach indices repeat the firm’s disclosure without a standardized public victim count; categories referenced in notification templates typically included payment-card and contact-order data for online shoppers.
Root cause
Unauthorized access to card-processing segment of online retail systems (per regulatory sample letters)