← Cricut

2017 Provo Craft & Novelty (Cricut) — e-commerce environment incident

2017 Unknown records affected Share on X

Data compromised

Online order and payment-card data classes per state-filed consumer notices

Technical writeup

Provo Craft & Novelty, Inc. d/b/a Cricut notified California and other regulators of a May 27, 2017, cybersecurity incident affecting its e-commerce environment, with substitute and consumer letters appearing from October 2017 onward. Public breach indices repeat the firm’s disclosure without a standardized public victim count; categories referenced in notification templates typically included payment-card and contact-order data for online shoppers.

Root cause

Unauthorized access to card-processing segment of online retail systems (per regulatory sample letters)

References